Google released Chrome 152.0.7977.75/.76 for Windows and macOS and 152.0.7977.75 for Linux, patching 26 vulnerabilities. The fixes include critical use-after-free flaws in Shared Tab Groups (CVE-2026-84353) and WebGL (CVE-2026-84352), which could allow malicious web content to crash the browser, disclose information, or potentially execute code in the browser process.
The release also addresses nine high-severity issues and additional flaws affecting FileSystem, Skia, Omnibox, V8, GPU, WebRTC, Downloads, and TabStrip, including risks of code execution and security-control bypass. Google has not reported active exploitation; organizations should verify managed endpoints update to Chrome 152.0.7977.75 or later as the Stable-channel rollout progresses.

See affected versions and whether adversaries are exploiting it.
15 events from the most recent confirmed update back to the earliest known activity.
CVE-2026-85049 was recorded as a high-severity use-after-free vulnerability in Chrome's Skia component affecting versions before 152.0.7977.82. A crafted HTML page can lead to arbitrary code execution within Chrome's sandbox; CISA's SSVC record reported no known exploitation.
FreeBSD published security fixes for its Chromium and ungoogled-chromium packages covering CVE-2026-84323 through CVE-2026-84335 and CVE-2026-84347 through CVE-2026-84359. The notice reported no known exploits and included critical CVE-2026-84325, rated CVSS 9.8.
The Canadian Centre for Cyber Security published advisory AV26-874 concerning vulnerabilities affecting Google Chrome versions before 152.0.7977.75. It advised users and administrators to review Google's Stable Channel Update for Desktop and apply available updates.
CVE-2026-84351 was published as an unpatched vulnerability affecting Chromium on Debian Linux 14.0. Tenable rated it CVSS 8.3, assessed it as network-accessible with high attack complexity and required user interaction, and reported no publicly known exploits.
CVE-2026-84352 was published as an unpatched vulnerability affecting Debian Linux 14.0 systems using Debian's Chromium package. Tenable assessed it as network-accessible with low attack complexity and required user interaction, and reported no known exploits.
CVE-2026-84331 was published as an unpatched vulnerability affecting Debian Linux 14.0 systems using Debian's Chromium package. Tenable assessed it as network-accessible with high attack complexity and required user interaction, and reported no known exploits.
CVE-2026-84353 was published as an unpatched vulnerability affecting Chromium on Debian Linux 14.0. Tenable assessed it as network-accessible with low attack complexity and required user interaction, with no known exploits available.
CVE-2026-84349 was published as an unpatched vulnerability affecting Chromium associated with Debian Linux 14.0. Tenable rated it CVSS 8.3, assessed it as network-accessible with high attack complexity and required user interaction, and reported no known public exploits.
CVE-2026-84329 was published as an unpatched vulnerability affecting Chromium installations on Debian Linux 14.0. Tenable rated it as remotely reachable with high attack complexity and required user interaction, and reported no known exploits.
The CVE record for critical Shared Tab Groups use-after-free CVE-2026-84353 identified Chrome for Android versions before 152.0.7977.75 as affected. It stated that a remote attacker could use a crafted HTML page and social engineering to execute arbitrary code outside Chrome's sandbox.
The CVE record for critical WebGL use-after-free CVE-2026-84352 identified Chrome for Android versions before 152.0.7977.75 as affected. It stated that a remote attacker could use a crafted HTML page to execute arbitrary code outside Chrome's sandbox.
Fedora security advisory FEDORA-2026-ee60d45695 referenced Chromium-related CVEs spanning the 76017–76023, 78891–78905, 79087–79106, 79246–79259, and 84323–84359 ranges. The supplied reference did not identify affected package versions, fixes, severity, or exploitation evidence.
The Guyana National CIRT issued a notice recommending that users and administrators review and apply Google's Chrome Stable Channel update for versions earlier than 152.0.7977.75 where necessary.
Mozilla released Firefox 155, fixing 29 security vulnerabilities, including 13 high-severity use-after-free, sandbox-escape, and memory-corruption issues. It also released patched Firefox ESR 115.40, 140.15, and 153.2, along with Thunderbird 155, 140.15, and 153.2; Mozilla reported no known in-the-wild exploitation.
Google released Chrome 152.0.7977.75/.76 for Windows and macOS and 152.0.7977.75 for Linux, addressing 26 vulnerabilities. The fixes include critical use-after-free flaws CVE-2026-84353 in Shared Tab Groups and CVE-2026-84352 in WebGL; no active exploitation was reported.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
20 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcecvefeed.io
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourcechromereleases.googleblog.com
Open sourcecirt.gy
Open sourcecve.org
Open sourcecve.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.