Google released security updates for Chrome 149 to fix multiple vulnerabilities affecting Windows, macOS, and Linux, warning that successful exploitation could lead to spoofing, denial of service, memory corruption, information disclosure, security bypass, or arbitrary code execution via a crafted HTML page. The June 7 advisory identified Chrome 149.0.7827.53/54 for Windows and macOS and 149.0.7827.53 for Linux as the patched versions.
The update notably addressed CVE-2026-10881, an out-of-bounds read/write flaw in ANGLE, and CVE-2026-11250, an inappropriate implementation issue in DevTools; both were highlighted with a CVSS 9.6 severity rating. A follow-on Chrome security update notice was also issued on June 14, reinforcing the need for organizations to validate and deploy the latest browser patches promptly after testing.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
On June 25, 2026, Google released Chrome 149.0.7827.196/197 for Windows and Mac and 149.0.7827.196 for Linux. The update addressed vulnerabilities including CVE-2026-13028 in WebGL and CVE-2026-13031 in Blink, which could allow denial of service, information disclosure, security bypass, or arbitrary code execution via a crafted HTML page.
On June 24, 2026, Google released Chrome 149.0.7827.155/.156 for Windows and Mac and 149.0.7827.155 for Linux. The update fixed multiple vulnerabilities, including CVE-2026-12440 in Chrome Digital Credentials and CVE-2026-12448 in Chrome WebView, with potential impacts including security bypass, privilege escalation, information disclosure, and arbitrary code execution.
On June 14, 2026, Google released Chrome 149.0.7827.114/.115 for Windows and Mac and 149.0.7827.114 for Linux. The update fixed multiple vulnerabilities, including CVE-2026-12027 in Chrome Headless and CVE-2026-12007 in Chrome Core, with potential impacts including denial-of-service, memory corruption, privilege escalation, information disclosure, security bypass, and arbitrary code execution.
On June 7, 2026, Google released a Chrome security update for version 149.0.7827.53/54 on Windows and Mac and 149.0.7827.53 on Linux. The update addressed multiple flaws, including CVE-2026-10881 in ANGLE and CVE-2026-11250 in DevTools, which could enable spoofing, denial-of-service, memory corruption, information disclosure, security bypass, or arbitrary code execution via a crafted HTML page.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
6 references tracked. Mallory keeps watching after this page renders.
egfincirt.org.eg
Open sourceegfincirt.org.eg
Open sourceegfincirt-wpn.azurewebsites.net
Open sourceegfincirt.org.eg
Open sourcechromereleases.googleblog.com
Open sourceegfincirt.org.eg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.