Chrome Update 149.0.7827.102 Addresses 17 Critical Vulnerabilities

Google has released Chrome 149.0.7827.102, addressing 74 vulnerabilities, 17 of which are marked as critical. Considering the issues fixed last week, Chrome has eliminated 39 critical vulnerabilities this month, surpassing the number in the past 10 years since the project's inception. Critical issues can bypass all layers of browser protection and execute code in the system outside the sandbox environment. Details are not yet disclosed, but it is known that the vulnerabilities are caused by use-after-free memory access in components and APIs such as Ozone, Aura, File Input, TabStrip, Bluetooth, Gamepad, Autofill, Views, Printing, Compositing, Web Apps, and Proxy.

Notably, there is a critical vulnerability CVE-2026-11640, caused by an integer overflow in the libyuv library, affecting not just browsers on the Chromium engine but potentially other projects utilizing this library for scaling and transforming video frames, such as Android, VLC, and Telegram.

It is also mentioned that one of the dangerous vulnerabilities (CVE-2026-11645), caused by a buffer overflow in the V8 engine, was exploited in an attack against browser users before the fix was published (0-day).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster