
[CIVN-2026-0294] Multiple Vulnerabilities in Google Chrome for Desktop
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Google Chrome for Desktop
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Google Chrome versions prior to 148.0.7778.215 for Linux
Google Chrome versions prior to 148.0.7778.215/216 for Mac
Google Chrome versions prior to 148.0.7778.216/217 for Windows
Overview
Multiple vulnerabilities have been reported in Google Chrome which could allow a remote attacker to execute arbitrary code, cause denial of service (DoS), leak sensitive information, or bypass security restrictions on the targeted system.
Target Audience:
All end-user organizations and individuals using Google Chrome for Desktop.
Risk Assessment:
Potential for remote code execution, memory corruption, unauthorized access to sensitive data and security bypass.
Impact Assessment:
System compromise or service disruption.
Description
Google Chrome is a popular internet browser used for accessing information on the World Wide Web. It is designed for use on desktop systems including Windows, macOS and Linux.
Multiple vulnerabilities exist in Google Chrome due to Out of bounds write and read, use after free, heap buffer overflow, type confusion, integer overflow, and uninitialized memory issues across multiple components including GPU, ANGLE, V8, Skia, Blink, WebGL, WebRTC, WebCodecs, WebAudio, PDFium, Media, Network, Extensions, Accessibility, UI, Storage, Input, Navigation, Printing, USB, and other browser subsystems. Several issues also arise from insufficient validation of untrusted input and inappropriate implementation in rendering, media, and browser process components. A remote attacker could exploit these vulnerabilities by convincing a victim to open a specially crafted web request.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code, cause denial of service (DoS), leak sensitive information, or bypass security restrictions on the targeted system.
Solution
Apply appropriate updates as mentioned as mentioned by the Vendor:
https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0877304591.html
Vendor Information
Google Chrome
https://chromereleases.googleblog.com/
References
https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0877304591.html
CVE Name
CVE-2026-9872
CVE-2026-9873
CVE-2026-9874
CVE-2026-9875
CVE-2026-9876
CVE-2026-9877
CVE-2026-9878
CVE-2026-9879
CVE-2026-9880
CVE-2026-9881
CVE-2026-9882
CVE-2026-9883
CVE-2026-9884
CVE-2026-9885
CVE-2026-9886
CVE-2026-9887
CVE-2026-9888
CVE-2026-9889
CVE-2026-9890
CVE-2026-9891
CVE-2026-9892
CVE-2026-9893
CVE-2026-9894
CVE-2026-9895
CVE-2026-9896
CVE-2026-9897
CVE-2026-9898
CVE-2026-9899
CVE-2026-9900
CVE-2026-9901
CVE-2026-9902
CVE-2026-9903
CVE-2026-9904
CVE-2026-9905
CVE-2026-9906
CVE-2026-9907
CVE-2026-9908
CVE-2026-9909
CVE-2026-9910
CVE-2026-9911
CVE-2026-9912
CVE-2026-9913
CVE-2026-9914
CVE-2026-9915
CVE-2026-9916
CVE-2026-9917
CVE-2026-9918
CVE-2026-9919
CVE-2026-9920
CVE-2026-9921
CVE-2026-9922
CVE-2026-9923
CVE-2026-9924
CVE-2026-9925
CVE-2026-9926
CVE-2026-9927
CVE-2026-9928
CVE-2026-9929
CVE-2026-9930
CVE-2026-9931
CVE-2026-9932
CVE-2026-9933
CVE-2026-9934
CVE-2026-9935
CVE-2026-9936
CVE-2026-9937
CVE-2026-9938
CVE-2026-9939
CVE-2026-9940
CVE-2026-9941
CVE-2026-9942
CVE-2026-9943
CVE-2026-9944
CVE-2026-9945
CVE-2026-9946
CVE-2026-9947
CVE-2026-9948
CVE-2026-9950
CVE-2026-9951
CVE-2026-9952
CVE-2026-9953
CVE-2026-9954
CVE-2026-9955
CVE-2026-9956
CVE-2026-9957
CVE-2026-9958
CVE-2026-9959
CVE-2026-9960
CVE-2026-9961
CVE-2026-9962
CVE-2026-10000
CVE-2026-10001
CVE-2026-10002
CVE-2026-10003
CVE-2026-10004
CVE-2026-10005
CVE-2026-10006
CVE-2026-10007
CVE-2026-10008
CVE-2026-10009
CVE-2026-10010
CVE-2026-10011
CVE-2026-10012
CVE-2026-10013
CVE-2026-10014
CVE-2026-10015
CVE-2026-10016
CVE-2026-10017
CVE-2026-10018
CVE-2026-10019
CVE-2026-10020
CVE-2026-10021
CVE-2026-10022
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmooImQACgkQ3jCgcSdc
ys+nihAAnAZI2LyGNdH9Ol8xWUbPIblfzY9c262D6P7XTcFPZECvdh+bi9oeYaow
d38J7xoLEF7oNJjyQSEXcJ5oBNp+sILgx+0GTrZE9I7XH0Ff3+IwCTIqZcfCIJe4
ZwRsaFi3jYAsYgy5wYWI0hCqCjDr3lH1F+ejWo/Xn0J95rARnxS3MJwLb1PGe6C8
Wht46R4VapTK2d8L+XhUjY86fRv4slG8+KFPzvbB6u/GC6+RE3v5mnHI1J9Vz7JE
KmtkA2lXTr/QYfekqrPBtIjC3WxdEtJkIKSPQHbonB2+nPN2D99E35d0zcTYf6+Y
q5QotyT9OqAinnNMMgEOAuYO2IojEGhhm6ylnMn8GXw7jAZ3JzvCR2lUDCsOUKpT
Tovsp+MLb6U+GirJwpCL1UUDfWwdATX6MB9FHbwpe8SMJS39Rx/77e2rsQjwCIwF
1c6/c6PDD/Hpakj+M2XI5pDO2mTb2cfzRYywdWYA6/hNO/1NIekvaXa00L3Mzy60
P8mPBGEREi3l8+c2NTuVMl35DvWNwq+8pEA8nW1bF4ywa+BfB5mUXNzZjiOPOPWc
TWjAxy1l54u2NWtncLkIpGLWZFDTKzDdoi9rKU2RVNZJMNE9IiNDPvJAcUyIEOsc
Ug4GHK2+BQHJ04yx+XN5eamkHsiDX3awA6pdXgoSdetkmFYAh3Q=
=haPb
—–END PGP SIGNATURE—–


