
[CIVN-2026-0443] Multiple Vulnerabilities in Google Chrome for Desktop
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Google Chrome for Desktop
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Google Chrome versions prior to 152.0.7977.75/.76 for Windows and Mac
Google Chrome versions prior to 152.0.7977.75 for Linux
Overview
Multiple vulnerabilities have been reported in Google which could allow a remote attacker to execute arbitrary code, elevate privileges, obtain sensitive information, bypass security restrictions, perform spoofing attacks or cause denial of service (DoS) conditions on the targeted system.
Target Audience:
All end-user organizations and individuals using Google Chrome for Desktop.
Risk Assessment:
High risk of unauthorized access to sensitive data, system compromise.
Impact Assessment:
Potential for remote code execution and denial of service (DoS).
Description
Google Chrome is a popular internet browser used for accessing information on the World Wide Web. It is designed for use on desktop systems including Windows, macOS and Linux.
Multiple vulnerabilities exist in Google Chrome due to Use after free in Shared Tab Groups, WebGL, Proxy, Browser, Dawn, WebRTC, TabStrip; Incorrect authorization in FileSystem, Navigation, SiteSettings, Chromoting, TabStrip; Information leak in Skia, MediaCapture; Improper input validation in Omnibox, DataTransfer; Improper privilege management in Downloads; Uninitialized resource in V8; Buffer overflow in GPU; Missing authorization in FileSystem; UI misrepresentation in FullScreen and Confused deputy in CredentialProvider. A remote attacker could exploit these vulnerabilities by convincing a victim to open a specially crafted web request.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code, elevate privileges, obtain sensitive information, bypass security restrictions, perform spoofing attacks or cause denial of service (DoS) conditions on the targeted system.
Solution
Apply appropriate as mentioned by the vendor:
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html
Vendor Information
Google Chrome
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html
References
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html
CVE Name
CVE-2026-84323
CVE-2026-84324
CVE-2026-84325
CVE-2026-84326
CVE-2026-84327
CVE-2026-84328
CVE-2026-84329
CVE-2026-84330
CVE-2026-84331
CVE-2026-84332
CVE-2026-84333
CVE-2026-84334
CVE-2026-84335
CVE-2026-84347
CVE-2026-84348
CVE-2026-84349
CVE-2026-84350
CVE-2026-84351
CVE-2026-84352
CVE-2026-84353
CVE-2026-84354
CVE-2026-84355
CVE-2026-84356
CVE-2026-84357
CVE-2026-84358
CVE-2026-84359
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqe2DIACgkQ3jCgcSdc
ys9QpQ/8DnAxiM9KkRlSC2OJQRQWabLyYGgL41W6POraDmg91GczVh6g0wcx4z/Z
zS9UyX7h1nF0uN/khqmUs9s7YBibi2al1q8Aapdaj0M3ZeNSyEBaZy5Nv4jd0KNf
ydCcQjWBXJYVbwcjOWd7l7aBnWc9LSsn+vFnVDYYP2mvOq7ZDTSooq4zXLXr/lZB
t5ZPf02K+xc4Mi87E8BiKmRPJ1BZCBOwsalAKgGbehCJtr691K5+cD/pVicOxCaE
dvYVRajBu8EDByG9ZzrBo6eYOd71/ToXJmtneqNx1K4f8zr9ghKXhhN2t8bYjeTx
mPwM2Uk/XOHF7h2TxMuCDS4818nM0NrxmePzJTxO8AMruO0R09yXmh/u9ByVvhDE
hX+D8bfWiFNTorZfrwrStrR/Phn5syeAIHycm14dLCF24LS61fsTQ1jmyW0a9F4w
t9wdKNay6g2B1WY294I7xp6msxn3xcQQW7mR2NTO8ErKGcuV4Ix3wnRKF5tCMaxM
qTL6IWthjqA8J2S0RsJpqY7TRLp/zYyBLkWJ26Z4SHbRZozK+eMSZwkCK9IvHP7y
8tedfthW0JIdTODHx/KDV6GL6vvb8v39pQ3/KJHylPw7f+jy+9Guf2dkg3Qeaopt
H0+3gnvYj9nK3/W7VvS3qKBOB8vqJmQVmrfgu2GDcvOACmSlmEQ=
=k8mc
—–END PGP SIGNATURE—–


