[CIVN-2026-0316] Multiple Vulnerabilities in Google Chrome for Desktop

By Published On: June 16, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Google Chrome for Desktop


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Google Chrome versions prior to 149.0.7827.102/103 for Windows and Mac 

Google Chrome versions prior to 149.0.7827.102 for Linux

Overview


Multiple vulnerabilities have been reported in Google Chrome which could allow a remote attacker to execute arbitrary code, obtain sensitive information, bypass security restriction, or cause Denial-of-Service (DoS) condition on the targeted system.


Target Audience:

All end-user organizations and individuals using Google Chrome for Desktop.


Risk Assessment:

High risk of remote code execution, unauthorized access to sensitive data, disruption of services, privilege escalation.


Impact Assessment:

Potential for system compromise or service disruption.


Description


Google Chrome is a popular internet browser used for accessing information on the World Wide Web. It is designed for use on desktop systems including Windows, macOS and Linux.


Multiple vulnerabilities exist in Google Chrome due to use-after-free (UAF) vulnerabilities, out-of-bounds read and write, integer overflow, type confusion, insufficient validation of untrusted input, race conditions, uninitialized memory usage, Out of bounds memory access, inappropriate implementation, object lifecycle issues, and insufficient policy enforcement across multiple components including Ozone, File Input, Aura, TabStrip, Bluetooth, Gamepad, Autofill, Views, Printing, Compositing, V8, GPU, Network, Extensions, CameraCapture, ServiceWorker, Payments, Skia, Dawn, WebRTC, Media, Codecs, PDF, Navigation, Guest View, SVG, Passwords, Plugins, and others. A remote attacker could exploit these vulnerabilities by convincing a victim to open a specially crafted web request.


Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code, obtain sensitive information, bypass security restriction, or cause Denial-of-Service (DoS) condition on the targeted system.

Note: This vulnerability (CVE-2026-11645) is being actively exploited in the wild. Users are strongly advised to apply the latest patches immediately.


Solution


Apply appropriate updates as mentioned by the vendor:

https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html



Vendor Information


Google Chrome

https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html


References


Google Chrome

https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html


CVE Name

CVE-2026-11628

CVE-2026-11629

CVE-2026-11630

CVE-2026-11631

CVE-2026-11632

CVE-2026-11633

CVE-2026-11634

CVE-2026-11635

CVE-2026-11636

CVE-2026-11637

CVE-2026-11638

CVE-2026-11639

CVE-2026-11640

CVE-2026-11641

CVE-2026-11642

CVE-2026-11643

CVE-2026-11644

CVE-2026-11645

CVE-2026-11646

CVE-2026-11647

CVE-2026-11648

CVE-2026-11649

CVE-2026-11650

CVE-2026-11651

CVE-2026-11652

CVE-2026-11653

CVE-2026-11654

CVE-2026-11655

CVE-2026-11656

CVE-2026-11657

CVE-2026-11658

CVE-2026-11659

CVE-2026-11660

CVE-2026-11661

CVE-2026-11662

CVE-2026-11663

CVE-2026-11664

CVE-2026-11665

CVE-2026-11666

CVE-2026-11667

CVE-2026-11668

CVE-2026-11669

CVE-2026-11670

CVE-2026-11671

CVE-2026-11672

CVE-2026-11673

CVE-2026-11674

CVE-2026-11675

CVE-2026-11676

CVE-2026-11677

CVE-2026-11678

CVE-2026-11679

CVE-2026-11680

CVE-2026-11681

CVE-2026-11682

CVE-2026-11683

CVE-2026-11684

CVE-2026-11685

CVE-2026-11686

CVE-2026-11687

CVE-2026-11688

CVE-2026-11689

CVE-2026-11690

CVE-2026-11691

CVE-2026-11692

CVE-2026-11693

CVE-2026-11694

CVE-2026-11695

CVE-2026-11696

CVE-2026-11697

CVE-2026-11698

CVE-2026-11699

CVE-2026-11700

CVE-2026-11701




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmoxaO8ACgkQ3jCgcSdc

ys82jRAAhfu5rMT2/rbfiE6kLq24WyS3LykaQnEdTbmot9jEqxQrArAeSFAm5wM1

RwT6QFABSB51icgZo31yey9G0LkbVURWl95Ml/iUryQkwNsQvA35cs1MZWwm9S5l

s+czTKMF5IkFtXSo6089zRDCUVhlgEL9DMCx8HZDciaC74dRZIVGtLDuQsK7/cl+

l9Y8oEeqDOJX9AWCgWkffDEA2pu7jBGURHKwr6VnZTuLnR4eLRQTgSJC9oI4gF72

KKEdv4p+nYUzapcUC5SrqE8lSZlS7Q2lhv9+Dq/70oSLZQTftaHFXcqrCOV4rggo

Mg56RgGNHbWDf7du6tmX1nlbObIW0A4RinDGEyAq3k0JNbCJgUwRzAqiBMRkUqsk

IAhJC7skIj8pfQF+sPl79VtY0kx6DD+17GSaZhL6/+Vy3unGTl3oAQg4JWOTaa0o

XCd5npxEYdXe85aZbSflvTRLSdUmm0cfV2Pvdj4kF/x2t/Ola41x4TC6/O7yUiMX

/clT0/zlxpr8nHsQDb5WNMRMPMOBqzMD4dLkDA4tOfCr70pL887YXc2kv4ve/y4X

wIaKc8HRyKiVmbXySMStMIVNxGiITvd5kPiHb+5IsDdvvpObGbzFS+2L0k7rG0ib

lBlqup3oXkB4ltveduaNIfBsJJSSf1qkaYf069VYHUIgZ2rrBDY=

=xwAl

—–END PGP SIGNATURE—–

Share this article