
[CIVN-2026-0377] Multiple Vulnerabilities in Google Chrome for Desktop
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Google Chrome for Desktop
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Google Chrome versions prior to 150.0.7871.181/.182 for Windows and Mac
Google Chrome versions prior to 150.0.7871.181 for Linux
Overview
Multiple vulnerabilities have been reported in Google which could allow a remote attacker to execute arbitrary code, bypass security restrictions on the targeted system.
Target Audience:
All end-user organizations and individuals using Google Chrome for Desktop.
Risk Assessment:
Potential for unauthorized access and bypass security restriction.
Impact Assessment:
Potential for remote code execution and bypass security restrictions.
Description
Google Chrome is a popular internet browser used for accessing information on the World Wide Web. It is designed for use on desktop systems including Windows, macOS and Linux.
Multiple vulnerabilities exist in Google Chrome due to type Confusion in WebAudio, inappropriate implementation in WebAudio, out of bounds write in ANGLE, read and write in ANGLE, Insufficient validation of untrusted input in Chromecast, Integer overflow in Chromecast, Uninitialized Use in Skia, Stack buffer overflow in V8 and Use after free in UI. A remote attacker could exploit these vulnerabilities by convincing a victim to open a specially crafted web page.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code, bypass security restrictions on the targeted system.
Solution
Apply appropriate as mentioned by the vendor:
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html
Vendor Information
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html
References
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0256605430.html
CVE Name
CVE-2026-16413
CVE-2026-16414
CVE-2026-16415
CVE-2026-16416
CVE-2026-16417
CVE-2026-16418
CVE-2026-16419
CVE-2026-16420
CVE-2026-16421
CVE-2026-16422
CVE-2026-16423
CVE-2026-16424
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpjbP0ACgkQ3jCgcSdc
ys8Apg//T8YpcPigRxbLGo0aTwvbHtbTyOjTDZ6eOJ+nz0L/byGLfQOzspSExSzT
HISqLIKGGf2qBLxuTV/KwKrOd+3dQRzmO/+ST2xdg5cLmNH92hcAzLum8NyAM9SP
8wBwBSG8S+60GfQi6Fw0egghlqd/h4zpZIGAKEZKO8OaQg5/4A7Abzzd5iAlmI1Q
vCTP85vklUPT2AfBvZz0K0lYbNHua+LHoAj42OLwUhFo/9Nx5wRHxY0KKwc4tXTr
LWDUU+qkKfGadJgFu9yxtoA9h7ukj/IipZEmzELdUclQvSv316a7r0z9EsCp5l5n
ghHfsnTulJ9i4Xq0vBnyPEaNH0wkmi7DnQ4ieE8xi3GdFa9/u4RfZA1PWSwaWjFN
LsKrIGuasP9BE84nbIga/wGD8XlgGpQtm4sSj6zLki2aEE3LWJu7uF0TBBB1wT1T
AH9QQRr+P5yAsprPETwXeYsyScaaL5gMVA1bh2xrjT5EpvAlCSA3ZdwnbU4pgqtv
hAqdpx1p3rRXwiq5fnJRIzIz0NcM/L8VdyaP2SAxoMOvGg1jQgDkgeVDkI4qxA6h
9Zq5RUR5LxsoT3bPXlZEMcOAGPoRZpxfOGppHWvn3TzEzYVJ7oEB1c0eOaQg5U37
YS0rXkQfEqMiEJjtG5VkkRav/g4jRjT9+WoOJF8YMaizbnS1kiI=
=semz
—–END PGP SIGNATURE—–


