[CIVN-2026-0420] Multiple vulnerabilities in Google Chrome for Desktop

By Published On: August 25, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple vulnerabilities in Google Chrome for Desktop


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Google Chrome versions prior to 151.0.7922.173/.174 for Windows and Mac

Google Chrome versions prior to 151.0.7922.173 for Linux

Overview


Multiple vulnerabilities have been reported in Google Chrome, which could allow a remote attacker to execute arbitrary code, elevate privileges, bypass security restrictions, or cause Denial of Service (DoS) condition on the targeted system.


Target Audience:

All end-user organizations and individuals using affected Google Chrome for Desktop.


Risk Assessment:

Potential for unauthorized access to data, remote code execution, disruption of services.


Impact Assessment:

High risk of system compromise, data theft, service disruption.


Description


Google Chrome is a popular internet browser that is used for accessing the information available on the World Wide Web. It is designed for use on desktop computers, such as those running on Windows, macOS, or Linux operating systems.


These vulnerabilities exist in Google Chrome due to use after free in Chromoting, privilege elevation in Import, incorrect authorization in Workers, race condition in V8, use after free in DOM, buffer overflow in Network, and improper resource control in Linux Toolkit Theming. A remote attacker could exploit these vulnerabilities by persuading a victim to visit a specially crafted webpage.


Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code, elevate privileges, bypass security restrictions, or cause Denial of Service (DoS) condition on the targeted system.


Solution


Apply appropriate updates as mentioned by the vendor.

https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0404570826.html



Vendor Information


Google Chrome

https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0404570826.html


References


Google Chrome

https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0404570826.html


CVE Name

CVE-2026-76017

CVE-2026-76018

CVE-2026-76019

CVE-2026-76020

CVE-2026-76021

CVE-2026-76022

CVE-2026-76023




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqNpeAACgkQ3jCgcSdc

ys/hBw//eMnNCFVGgZXfQt5ua/0xZHEozskJec/2ysrzExqSrrICdz09rlv6kzHK

3r6FircptyPWzUozFaJuGW8bRYop0Xqe47/SLrySBKndj++zDoWWjy22JC3vcQDk

Ks7lDZRzvhmbmVN/1l1oDz3rMUgiIh1RAjBQsNrVlApZiFtA5BWUd754a2lAumbj

As2gaQNs/tKdIQuuAjkQwtOlgmQfIRC3bLpgfagTdhY1xsI8MJifYnK3i2WQOZCN

tY65YKwb/9qk8K/8X7qZbfdksm8IkjNQBvtxjUxcTClzqIRVNzOjI/R77AHGFw3Y

gYHVVCmEeBt9HYmoNHDz8lPZgfEAlnx0PX1Hw+1zzAUPX+utF96JaP+qfGJT9Ixw

u3yV5Ac8t+dxbGpLZD96fmNcGr5CiiKJFimw5AUwd2aqQ8jeYltvEhorsEjPRcJY

fxzbqZ9WhwwYXpPZVk0rpxD3VWQ8g3F2XSW3e2JeJuBVxQe2fhvL6ErPUz4+JYJW

CCyqDUofO7CtBQ2aqyN0B7KT8q2Jxx5qipFi897V+M0ktFeATcrpetxKoHyPRb9x

6yOvKWsmkGqauMGjG++toMUZQFSRBWSL2iBh+lvB8b18X+WrfeqY4qwDnuyPrOgt

4Kg5kHgFkdBiHdWdK7/FRwlWC+6QUdUV3Z+uLX/YsepWZhytRKU=

=QKcs

—–END PGP SIGNATURE—–

Share this article