CERT-In Vulnerability Note
CIVN-2026-0427
Multiple Vulnerabilities in Google Chrome for Desktop
Original Issue Date:August 27, 2026
Severity Rating: HIGH
Software Affected
- Google Chrome versions prior to 152.0.7977.64/.65 for Windows and Mac
- Google Chrome versions prior to 152.0.7977.64 for Linux
Overview
Multiple Vulnerabilities have been reported in Google Chrome, which could allow a remote attacker to execute arbitrary code, elevate privileges, bypass security restrictions, or cause Denial of Service (DoS) condition on the targeted system.
Target Audience: All end user organizations and individuals using Google Chrome for Desktop.
Risk Assessment: Potential for unauthorized access to data, remote code execution, and disruption of services.
Impact Assessment: High risk of system compromise, data theft, and service disruption.
Description
Google Chrome is a popular internet browser that is used for accessing the information available on the World Wide Web. It is designed for use on Desktop computers, such as those running on Windows, macOS or Linux operating systems.
Multiple vulnerabilities exist in Google Chrome due to use-after-free in components including ANGLE, Aura, Chromecast, Safebrowsing, WebGL, V8 and more; out-of-bounds read in ANGLE, GPU, Skia, Media, FileSystem and Tint; uninitialized resource usage in GPU, Skia, ANGLE and more; improper input validation in Chromecast, Autofill, Media and more; incorrect authorization in Sandbox, USB, Extensions and more; and race conditions in WebAppInstalls, FileSystem, Workers and more. A remote attacker could exploit these vulnerabilities by persuading a victim to visit a specially crafted webpage.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code, elevate privileges, bypass security restrictions, or cause a Denial of Service (DoS) condition on the targeted system.
For complete list of affected products, CVEs, workarounds and solutions, refer to the Google Chrome for Desktop security updates.
https://chromereleases.googleblog.com/search?updated-max=2026-08-25T22:14:00-07:00&max-results=7
Solution
Apply appropriate updates as mentioned by the vendor:
https://chromereleases.googleblog.com/search?updated-max=2026-08-25T22:14:00-07:00&max-results=7
Vendor Information
Google Chrome
https://chromereleases.googleblog.com/search?updated-max=2026-08-25T22:14:00-07:00&max-results=7
References
Google Chrome
https://chromereleases.googleblog.com/search?updated-max=2026-08-25T22:14:00-07:00&max-results=7
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|