
[CIVN-2026-0272] Multiple Vulnerabilities in Google Chrome for Desktop
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Google Chrome for Desktop
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Google Chrome versions prior to 148.0.7778.178 for Linux
Google Chrome versions prior to 148.0.7778.178/179 for Windows and Mac
Overview
Multiple vulnerabilities have been reported in Google Chrome which could allow a remote attacker to execute arbitrary code, bypass security restrictions, obtain sensitive information, heap-based buffer overflow or cause Denial of Service (DoS) conditions on the targeted system.
Target Audience:
All end-user organizations and individuals using Google Chrome for Desktop.
Risk Assessment:
High risk of remote code execution, unauthorized access to sensitive data, disruption of services, privilege escalation.
Impact Assessment:
Potential for system compromise, service disruption, sensitive Information disclosure.
Description
Google Chrome is a popular internet browser used for accessing information on the World Wide Web. It is designed for use on desktop systems including Windows, macOS and Linux.
Multiple vulnerabilities exist in Google Chrome due to Use-after-free in WebRTC, GPU, QUIC, XR and DOM; Out-of-bounds read in GPU; Heap buffer overflow in WebRTC and Chromecast; Type confusion in GFX; Insufficient policy enforcement in Service Worker; Insufficient validation of untrusted input in Input; and Inappropriate implementation in UI. A remote attacker could exploit these vulnerabilities by convincing a victim to open a specially crafted web request.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code, bypass security restrictions, obtain sensitive information, heap-based buffer overflow or cause Denial of Service (DoS) conditions on the targeted system.
Solution
Apply appropriate updates as mentioned by the Vendor:
https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html
Vendor Information
Google Chrome
https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html
References
https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0841193308.html
CVE Name
CVE-2026-9111
CVE-2026-9112
CVE-2026-9110
CVE-2026-9113
CVE-2026-9114
CVE-2026-9115
CVE-2026-9116
CVE-2026-9117
CVE-2026-9118
CVE-2026-9119
CVE-2026-9120
CVE-2026-9121
CVE-2026-9122
CVE-2026-9123
CVE-2026-9124
CVE-2026-9126
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmoZaLIACgkQ3jCgcSdc
ys9MvRAAo66wxYN2QLEolXcjklv63jzkP61wW9IJgY20CH6NWIgeBiOtmbotCdcG
qyhr48bHHfOMpYDhFyswamcbyiQ5WTrxeJJCbaHH4QLKSiJY52XfAkqfpen6eat/
ZvbSNlwGeRDAh8WpBHdtizSR9Yd5Xl0/olurGDFaubh4XNoG6RckgCYdOAufhcX5
26F/fIjR6Lar7XXYDX+ZNvlppCjAVSXsIlZPuNVdbCeTic3bRtBrzjAdxspobJrc
yk6F0nSnkm+2G4ScM5bemB+s5jHhBAza177najKtQMgIx6LFXz9xlR0LdeMTJQDF
iyxMr6fFQJnE8V+Xls0jhTOoWry3vJCybaHgHztp9pZPS8qNzdt9Sxq5d+JezCcC
GcEO+8llC22Vy/9eibgi3/y+BDwmpoSfdW21fPTIdZqjPYe9BXswFSKBKzuNefM5
2rUd/qUwrVxyAVxXU3ZKVkYZjIuCZv0n/stL3weyvdSnF/0QXkU1hfbLssozizS+
2i2p3uAme0RT08Rqlsp9J7LUIrBDEHTLgBdInnNsDLSglk1f/a2leGmnM+YLpncj
mK+pIIoFgd5+rPnBTHgwr8gYOnitIeCW4nmDSgoHeTlnflzLPUfz15Vt57BilNJM
MSVl5z9t/JG92WL4tybeF5dNj50GDldt8CC43/C3k0bfJvIUjyg=
=RFwo
—–END PGP SIGNATURE—–


