June 5, 2026

PBX Science

VoIP & PBX, Networking, DIY, Computers.

Google Chrome 149 Fixes a Record-Breaking 429 Vulnerabilities — Update Now



Google Chrome 149 Patches Record 429 Vulnerabilities

Security // Browser Watch

Security Update

Google Chrome 149 Fixes a Record-Breaking 429 Vulnerabilities — Update Now

June 5, 2026 · Chrome 149.0.7827.53/54 · Windows · Mac · Linux

Google released Chrome 149 to the stable channel on June 2, 2026, patching 429 security vulnerabilities — the largest number ever addressed in a single Chrome update. Users across all desktop platforms are strongly advised to update immediately.

The sheer scale of this release is unprecedented. Chrome 149 surpasses the total count of all Chrome security fixes released in the entirety of 2025, in a single version bump. Security researchers and analysts attribute this surge partly to the increased use of AI-powered fuzzing tools, which have become significantly more effective at uncovering memory safety issues deep within the browser’s graphics, JavaScript, and networking subsystems.

No active exploitation of any of these vulnerabilities has been reported at the time of publication. However, with 22 Critical-rated flaws among the 429, the risk window between public disclosure and attempted exploitation is narrow — prompt updating is essential.

22 Critical
~90 High
~230 Medium
~87 Low
⚠ Action Required: Although no exploits are known in the wild, the 22 Critical-severity vulnerabilities in this release represent the highest possible risk rating. Google recommends all users update to Chrome 149 as soon as possible.

Critical Vulnerabilities (22 total)

The most severe flaw — CVE-2026-10881, rated CVSS 9.6 — is an out-of-bounds read and write in the ANGLE graphics engine. A remote attacker could exploit it via a crafted HTML page to escape Chrome’s sandbox and potentially execute arbitrary code on the host system. Google awarded the external researcher who reported it a $97,000 bug bounty. All 22 Critical vulnerabilities are listed below.

Critical 22 vulnerabilities
CVEDescriptionComponent
CVE-2026-10881Out of bounds read and writeANGLE
CVE-2026-10882Use after freeNetwork
CVE-2026-10883Out of bounds writeANGLE
CVE-2026-10884Use after freeChromecast
CVE-2026-10885Use after freeChrome for iOS
CVE-2026-10886Use after freeFileSystem
CVE-2026-10887Use after freeChromoting
CVE-2026-10888Use after freeCast Streaming
CVE-2026-10889Out of bounds readANGLE
CVE-2026-10890Use after freeCast
CVE-2026-10891Use after freeGFX
CVE-2026-10892Out of bounds writeGPU
CVE-2026-10893Use after freeChromoting
CVE-2026-10894Use after freePrinting
CVE-2026-10895Use after freeOzone
CVE-2026-10896Use after freeChrome for iOS
CVE-2026-10897Out of bounds writeGPU
CVE-2026-10898Stack buffer overflowGPU
CVE-2026-10899Use after freeOzone
CVE-2026-10900Use after freePasswords
CVE-2026-10901Use after freePasswords
CVE-2026-10902Use after freeOzone
High ~90 vulnerabilities (CVE-2026-10903 through CVE-2026-10989, selected)
CVEDescriptionComponent
CVE-2026-10903Use after freeWebRTC
CVE-2026-10904Inappropriate implementationV8
CVE-2026-10905Use after freeNetwork
CVE-2026-10906Use after freeWebAuthentication
CVE-2026-10907Out of bounds writeANGLE
CVE-2026-10910Type ConfusionV8
CVE-2026-10913Use after freeANGLE
CVE-2026-10921Integer overflowDawn
CVE-2026-10925Out of bounds writeSkia
CVE-2026-10929Heap buffer overflowANGLE
CVE-2026-10936Type ConfusionV8
CVE-2026-10946Heap buffer overflowMedia
CVE-2026-10949Heap buffer overflowVideo
CVE-2026-10955Type ConfusionANGLE
CVE-2026-10963Integer overflowV8
CVE-2026-10988Use after freeViews
CVE-2026-10989Inappropriate implementationV8

† Full list continues through CVE-2026-10989. Over 70 additional High-severity entries omitted for brevity; see the official Chrome release blog for the complete advisory.

Medium ~230 vulnerabilities (CVE-2026-10990 – CVE-2026-11215)

Medium-severity issues span a wide surface area including Use-after-free in V8, WebRTC, Autofill, Passwords, ANGLE, and Media; integer overflows in ANGLE, GPU, V8, Blink, and Chromoting; heap buffer overflows in Skia, TabStrip, and Extensions; type confusion in GPU, CSS, and Media; uninitialized use in ANGLE, Dawn, Skia, and GPU; and a broad range of insufficient validation and policy enforcement issues across nearly every Chrome subsystem. A full machine-readable list is available in the official Chrome advisory.

Low ~87 vulnerabilities (CVE-2026-11216 – CVE-2026-11309)

Low-severity entries include incorrect security UI issues in File Input, Tab Strip, Tab Hover Cards, WebUI, Passwords, and Downloads; policy bypass flaws in Permissions, SafeBrowsing, CSS, ServiceWorker, Sandbox, Shortcuts, Content Security Policy, and Blink; side-channel information leakage in PerformanceAPIs and Paint; use-after-free bugs in Chromoting, Extensions, Network, PDFium (5 separate entries), and Input; and miscellaneous insufficient validation flaws in Navigation, Extensions, Cast, and Wallet.

What Makes This Release Unusual

The 429-vulnerability count is not the result of a single security incident but rather reflects a sustained acceleration in Chrome’s internal bug discovery program. Google has been applying AI-assisted fuzzing extensively to its codebase, and the results are showing up in release notes at an unprecedented scale. Out of the 22 Critical flaws, only three were reported by external researchers; the remaining 19 were found internally. Among roughly 90 High-severity bugs, only 10 came from outside researchers, with the bulk of medium and low findings also originating from Google’s own tooling.

The top external bounty awarded in this release was $97,000 for CVE-2026-10881, reflecting both the severity of the ANGLE out-of-bounds flaw and Chrome’s continued investment in its bug bounty program.

Affected Versions and Available Updates

Windows
149.0.7827.53 / .54
macOS
149.0.7827.53 / .54
Linux
149.0.7827.53

Chrome is available free of charge from Google’s website for Windows, macOS, and Linux. Any installed version prior to those listed above is potentially vulnerable to all 429 flaws addressed in this release.

How to Update Chrome Now

Manual Update Instructions

1
Open Chrome and navigate to chrome://settings/help or go to Menu → Help → About Google Chrome.
2
Chrome will automatically detect and download the available update. Wait for the download to complete.
3
Click Relaunch to restart the browser and fully apply the update. The update is not active until Chrome is restarted.
4
Confirm the installed version reads 149.0.7827.53 (Linux / Mac) or 149.0.7827.54 (Windows) on the same About page.

Chrome updates automatically in the background when a new version is available, but the update does not take effect until the browser is restarted. Users who leave Chrome running for extended periods may be on a vulnerable version even after the update has been downloaded. Restarting Chrome ensures the fix is applied.

Bottom line: With 22 Critical-rated flaws — any one of which could allow a remote attacker to escape Chrome’s sandbox via a malicious web page — this is one of the most significant Chrome security releases in the browser’s history. Update as soon as possible and restart Chrome to complete the process.
Sources: Google Chrome Releases Blog · SecurityWeek · Canadian Centre for Cyber Security (AV26-544)  ·  Published June 5, 2026

Google Chrome 149 Fixes a Record-Breaking 429 Vulnerabilities — Update Now.  Google released Chrome 149 to the stable channel on June 2, 2026, patching 429 security vulnerabilities — the largest number ever addressed in a single Chrome update. Users across all desktop platforms are strongly advised to update immediately.

Google Chrome 149 Fixes a Record-Breaking 429 Vulnerabilities — Update Now


Windows Software Alternatives in Linux


Disclaimer of pbxscience.com

PBXscience.com © All Copyrights Reserved. | Newsphere by AF themes.