Google Chrome — Stable Channel Update for Desktop

Stable Channel Update for Desktop

Fixed 19
  • Fixed use-after-free in ANGLE (CVE-2026-79282)
  • Fixed use-after-free in Aura (CVE-2026-79290)
  • Fixed use-after-free in Chromecast (CVE-2026-79054)
  • Fixed improper input validation in Chromecast (CVE-2026-79121)
  • Fixed use-after-free in Chromecast (CVE-2026-79224)
  • Fixed use-after-free in Aura (CVE-2026-79052)
Security 1
  • Fixed 327 security vulnerabilities including critical use-after-free issues in ANGLE, Aura, Chromecast, Views, Safebrowsing and other components

From Google Chrome

The Chrome team is delighted to announce the promotion of Chrome 152 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks. Chrome 152.0.7977.64 (Linux) 152.0.7977.64/.65 Windows/Mac contains a number of fixes and improvements -- a list of changes is available in thelog. Watch out for upcomingChrome andChromium blog posts about new features and big efforts delivered in 152. Security Fixes and Rewards Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed. This update includes 327 security fixes. Please see the Chrome Security Page for more information. [$25,000][496807874] Critical CVE-2026-79282: Use after free in ANGLE. Reported by Goodluck on 2026-03-27 [N/A][516427761] Critical CVE-2026-79290: Use after free in Aura. Reported by Google on 2026-05-25 [N/A][516764384] Critical CVE-2026-79054: Use after free in Chromecast. Reported by Google on 2026-05-26 [N/A][516777082] Critical CVE-2026-79121: Improper input validation in Chromecast. Reported by Google on 2026-05-26 [N/A][516988476] Critical CVE-2026-79224: Use after free in Chromecast. Reported by Google on 2026-05-27 [N/A][517518019] Critical CVE-2026-79052: Use after free in Aura. Reported by Google on 2026-05-28 [N/A][518006007] Critical CVE-2026-79150: Use after free in Views. Reported by Google on 2026-05-29 [N/A][522082472] Critical CVE-2026-78935: Use of uninitialized variable in Mobile. Reported by Google on 2026-06-10 [N/A][523704817] Critical CVE-2026-79012: Use after free in Safebrowsing. Reported by Google on 2026-06-13 [N/A][532921800] Critical CVE-2026-79200: Use after free in Aura. Reported by Google on 2026-07-09 [$1,000][532617619] High CVE-2026-78989: Out of bounds read in ANGLE. Reported by Đặng Thế Tuyến on 2026-07-09 [$500][508638064] High CVE-2026-79069: Memory corruption in Tint. Reported by andryskowski.michal on 2026-05-01 [N/A][498885920] High CVE-2026-79175: Type confusion in Accessibility. Reported by Google on 2026-04-02 [N/A][500311587] High CVE-2026-79218: Incorrect authorization in Sandbox. Reported by Google on 2026-04-07 [N/A][501892500] High CVE-2026-79195: Use after free in Script. Reported by Google on 2026-04-12 [N/A][513261751] High CVE-2026-78939: Use after free in Chromecast. Reported by Google on 2026-05-14 [N/A][515470739] High CVE-2026-79194: Use after free in Chromoting. Reported by Google on 2026-05-21 [N/A][515473074] High CVE-2026-79247: Use after free in Chromoting. Reported by Google on 2026-05-21 [N/A][516947491] High CVE-2026-79219: Use after free in Bluetooth. Reported by Google on 2026-05-27 [N/A][517515945] High CVE-2026-79047: Use after free in Views. Reported by Google on 2026-05-28 [N/A][517519352] High CVE-2026-79292: Integer overflow in Chromecast. Reported by Google on 2026-05-28 [N/A][517527943] High CVE-2026-78986: Uninitialized resource in GPU. Reported by Google on 2026-05-28 [N/A][517548647] High CVE-2026-79039: Use after free in Mobile. Reported by Google on 2026-05-28 [N/A][517550232] High CVE-2026-78934: Race condition in ReadAloud. Reported by Google on 2026-05-28 [N/A][517736936] High CVE-2026-79011: UI misrepresentation in Browser. Reported by Google on 2026-05-29 [N/A][517742721] High CVE-2026-78911: Incorrect authorization in USB. Reported by Google on 2026-05-29 [N/A][517959443] High CVE-2026-79257: Use after free in Views. Reported by Google on 2026-05-29 [N/A][521285077] High CVE-2026-79202: Use after free in Chromecast. Reported by Google on 2026-06-08 [N/A][521502218] High CVE-2026-79212: Missing authorization in Passwords. Reported by Google on 2026-06-08 [N/A][521942358] High CVE-2026-79183: Use after free in Accessibility. Reported by Google on 2026-06-09 [N/A][522294538] High CVE-2026-79155: Race condition in FileSystem. Reported by Google on 2026-06-10 [N/A][523095011] High CVE-2026-79093: Incorrect authorization in Paint. Reported by Google on 2026-06-12 [N/A][523266585] High CVE-2026-79019: Out of bounds write in ANGLE. Reported by Google on 2026-06-12 [N/A][523296105] High CVE-2026-79187: Use after free in WebRTC. Reported by Google on 2026-06-12 [N/A][523714535] High CVE-2026-79288: Improper input validation in Autofill. Reported by Google on 2026-06-14 [N/A][523717796] High CVE-2026-79130: Buffer overflow in ANGLE. Reported by Google on 2026-06-14 [N/A][523723064] High CVE-2026-78965: Uninitialized resource in ANGLE. Reported by Google on 2026-06-14 [N/A][523738212] High CVE-2026-79117: Race condition in WebAppInstalls. Reported by Google on 2026-06-14 [N/A][524698525] High CVE-2026-79082: Incorrect authorization in Transactions Platform. Reported by Google on 2026-06-16 [N/A][525683797] High CVE-2026-79111: Improper input validation in Dawn. Reported by Google on 2026-06-19 [N/A][528397177] High CVE-2026-79072: Improper state validation in Performance. Reported by Google on 2026-06-27 [N/A][529509587] High CVE-2026-79142: Buffer overflow in ANGLE. Reported by Google on 2026-06-30 [N/A][529991907] High CVE-2026-78948: Buffer overflow in WebGL. Reported by Google on 2026-07-01 [N/A][532904047] High CVE-2026-78908: Information leak in Canvas. Reported by Google on 2026-07-09 [N/A][532914190] High CVE-2026-78895: Information leak in Paint. Reported by Google on 2026-07-09 [N/A][532988552] High CVE-2026-79043: Out of bounds write in ANGLE. Reported by Google on 2026-07-09 [N/A][534468209] High CVE-2026-79235: Use after free in WebGL. Reported by Google on 2026-07-13 [N/A][534591074] High CVE-2026-79232: Use after free in Aura. Reported by Google on 2026-07-14 [N/A][535379043] High CVE-2026-79118: Uninitialized resource in ANGLE. Reported by Google on 2026-07-16 [TBD][535876894] High CVE-2026-79174: Incorrect authorization in Extensions. Reported by 章鱼哥@aipyaipy.com on 2026-07-17 [N/A][536428615] High CVE-2026-78900: Improper input validation in Media. Reported by Google on 2026-07-19 [N/A][536444272] High CVE-2026-79188: Out of bounds write in ANGLE. Reported by Google on 2026-07-19 [N/A][536505721] High CVE-2026-79189: Out of bounds write in ANGLE. Reported by Google on 2026-07-19 [N/A][536531630] High CVE-2026-79048: Out of bounds write in ANGLE. Reported by Google on 2026-07-19 [N/A][536532605] High CVE-2026-79240: Out of bounds write in ANGLE. Reported by Google on 2026-07-19 [N/A][536568319] High CVE-2026-79014: Race condition in Autofill. Reported by Google on 2026-07-19 [N/A][536606137] High CVE-2026-79198: Use after free in Platform. Reported by Google on 2026-07-19 [N/A][536626343] High CVE-2026-79131: Out of bounds write in ANGLE. Reported by Google on 2026-07-19 [N/A][536636648] High CVE-2026-79149: Use after free in ANGLE. Reported by Google on 2026-07-19 [N/A][536659904] High CVE-2026-79275: Use after free in ANGLE. Reported by Google on 2026-07-20 [N/A][536681676] High CVE-2026-79138: Out of bounds write in ANGLE. Reported by Google on 2026-07-20 [N/A][537109028] High CVE-2026-79026: Use after free in Extensions. Reported by Google on 2026-07-21 [TBD][537233963] High CVE-2026-79027: Use after free in WebRTC. Reported by Mozilla on 2026-07-21 [N/A][537835609] High CVE-2026-78904: Type confusion in ANGLE. Reported by Google on 2026-07-22 [TBD][540430406] High CVE-2026-78899: Use after free in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-07-29 [N/A][540870921] High CVE-2026-78954: Incorrect authorization in Extensions. Reported by Google on 2026-07-30 [TBD][543707066] High CVE-2026-79274: Information leak in GPU. Reported by weihengqiuu on 2026-08-07 [TBD][545767601] High CVE-2026-78938: Type confusion in V8. Reported by Zhenpeng (Leo) Lin at depthfirst on 2026-08-12 [TBD][545820931] High CVE-2026-78952: Out of bounds write in Crashpad. Reported by Brendan Dolan-Gavitt, XBOW on 2026-08-13 [TBD][546670199] High CVE-2026-79236: Type confusion in V8. Reported by Zhenpeng (Leo) Lin on 2026-08-14 [TBD][548340637] High CVE-2026-79078: Use after free in FedCM. Reported by m0omo0d on 2026-08-18

View original

Upgraded? How did it go?

Discussion