
[CIVN-2026-0316] Multiple Vulnerabilities in Google Chrome for Desktop
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Google Chrome for Desktop
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Google Chrome versions prior to 149.0.7827.102/103 for Windows and Mac
Google Chrome versions prior to 149.0.7827.102 for Linux
Overview
Multiple vulnerabilities have been reported in Google Chrome which could allow a remote attacker to execute arbitrary code, obtain sensitive information, bypass security restriction, or cause Denial-of-Service (DoS) condition on the targeted system.
Target Audience:
All end-user organizations and individuals using Google Chrome for Desktop.
Risk Assessment:
High risk of remote code execution, unauthorized access to sensitive data, disruption of services, privilege escalation.
Impact Assessment:
Potential for system compromise or service disruption.
Description
Google Chrome is a popular internet browser used for accessing information on the World Wide Web. It is designed for use on desktop systems including Windows, macOS and Linux.
Multiple vulnerabilities exist in Google Chrome due to use-after-free (UAF) vulnerabilities, out-of-bounds read and write, integer overflow, type confusion, insufficient validation of untrusted input, race conditions, uninitialized memory usage, Out of bounds memory access, inappropriate implementation, object lifecycle issues, and insufficient policy enforcement across multiple components including Ozone, File Input, Aura, TabStrip, Bluetooth, Gamepad, Autofill, Views, Printing, Compositing, V8, GPU, Network, Extensions, CameraCapture, ServiceWorker, Payments, Skia, Dawn, WebRTC, Media, Codecs, PDF, Navigation, Guest View, SVG, Passwords, Plugins, and others. A remote attacker could exploit these vulnerabilities by convincing a victim to open a specially crafted web request.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code, obtain sensitive information, bypass security restriction, or cause Denial-of-Service (DoS) condition on the targeted system.
Note: This vulnerability (CVE-2026-11645) is being actively exploited in the wild. Users are strongly advised to apply the latest patches immediately.
Solution
Apply appropriate updates as mentioned by the vendor:
https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html
Vendor Information
Google Chrome
https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html
References
Google Chrome
https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_0153744567.html
CVE Name
CVE-2026-11628
CVE-2026-11629
CVE-2026-11630
CVE-2026-11631
CVE-2026-11632
CVE-2026-11633
CVE-2026-11634
CVE-2026-11635
CVE-2026-11636
CVE-2026-11637
CVE-2026-11638
CVE-2026-11639
CVE-2026-11640
CVE-2026-11641
CVE-2026-11642
CVE-2026-11643
CVE-2026-11644
CVE-2026-11645
CVE-2026-11646
CVE-2026-11647
CVE-2026-11648
CVE-2026-11649
CVE-2026-11650
CVE-2026-11651
CVE-2026-11652
CVE-2026-11653
CVE-2026-11654
CVE-2026-11655
CVE-2026-11656
CVE-2026-11657
CVE-2026-11658
CVE-2026-11659
CVE-2026-11660
CVE-2026-11661
CVE-2026-11662
CVE-2026-11663
CVE-2026-11664
CVE-2026-11665
CVE-2026-11666
CVE-2026-11667
CVE-2026-11668
CVE-2026-11669
CVE-2026-11670
CVE-2026-11671
CVE-2026-11672
CVE-2026-11673
CVE-2026-11674
CVE-2026-11675
CVE-2026-11676
CVE-2026-11677
CVE-2026-11678
CVE-2026-11679
CVE-2026-11680
CVE-2026-11681
CVE-2026-11682
CVE-2026-11683
CVE-2026-11684
CVE-2026-11685
CVE-2026-11686
CVE-2026-11687
CVE-2026-11688
CVE-2026-11689
CVE-2026-11690
CVE-2026-11691
CVE-2026-11692
CVE-2026-11693
CVE-2026-11694
CVE-2026-11695
CVE-2026-11696
CVE-2026-11697
CVE-2026-11698
CVE-2026-11699
CVE-2026-11700
CVE-2026-11701
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmoxaO8ACgkQ3jCgcSdc
ys82jRAAhfu5rMT2/rbfiE6kLq24WyS3LykaQnEdTbmot9jEqxQrArAeSFAm5wM1
RwT6QFABSB51icgZo31yey9G0LkbVURWl95Ml/iUryQkwNsQvA35cs1MZWwm9S5l
s+czTKMF5IkFtXSo6089zRDCUVhlgEL9DMCx8HZDciaC74dRZIVGtLDuQsK7/cl+
l9Y8oEeqDOJX9AWCgWkffDEA2pu7jBGURHKwr6VnZTuLnR4eLRQTgSJC9oI4gF72
KKEdv4p+nYUzapcUC5SrqE8lSZlS7Q2lhv9+Dq/70oSLZQTftaHFXcqrCOV4rggo
Mg56RgGNHbWDf7du6tmX1nlbObIW0A4RinDGEyAq3k0JNbCJgUwRzAqiBMRkUqsk
IAhJC7skIj8pfQF+sPl79VtY0kx6DD+17GSaZhL6/+Vy3unGTl3oAQg4JWOTaa0o
XCd5npxEYdXe85aZbSflvTRLSdUmm0cfV2Pvdj4kF/x2t/Ola41x4TC6/O7yUiMX
/clT0/zlxpr8nHsQDb5WNMRMPMOBqzMD4dLkDA4tOfCr70pL887YXc2kv4ve/y4X
wIaKc8HRyKiVmbXySMStMIVNxGiITvd5kPiHb+5IsDdvvpObGbzFS+2L0k7rG0ib
lBlqup3oXkB4ltveduaNIfBsJJSSf1qkaYf069VYHUIgZ2rrBDY=
=xwAl
—–END PGP SIGNATURE—–


