Stable Channel Update for Desktop
- Fixed use after free in Shared Tab Groups (CVE-2026-84353)
- Fixed use after free in WebGL (CVE-2026-84352)
- Fixed incorrect authorization in FileSystem (CVE-2026-84354)
- Fixed information leak in Skia (CVE-2026-84359)
- Fixed improper input validation in Omnibox (CVE-2026-84357)
- Fixed use after free in Proxy (CVE-2026-84324)
- Fixed use after free in Browser (CVE-2026-84349)
- Fixed uninitialized resource in V8 (CVE-2026-84326)
- Fixed use after free in Dawn (CVE-2026-84333)
- Fixed buffer overflow in GPU (CVE-2026-84351)
- Fixed improper input validation in DataTransfer (CVE-2026-84325)
- Fixed missing authorization in FileSystem (CVE-2026-84328)
- Fixed use after free in WebRTC (CVE-2026-84347)
- Fixed missing authorization in FileSystem (CVE-2026-84323)
- Fixed incorrect authorization in Navigation (CVE-2026-84355)
- Fixed improper privilege management in Downloads (CVE-2026-84358)
- Fixed incorrect authorization in SiteSettings (CVE-2026-84332)
- Fixed UI misrepresentation in FullScreen (CVE-2026-84330)
- Fixed incorrect authorization in Chromoting (CVE-2026-84334)
- Fixed information leak in MediaCapture (CVE-2026-84348)
From Google Chrome
The Stable channel has been updated to 152.0.7977.75/.76 for Windows and Mac and 152.0.7977.75 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log Security Fixes and Rewards Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed. This update includes 26 security fixes. Please see the Chrome Security Page for more information. [N/A][522307103] Critical CVE-2026-84353: Use after free in Shared Tab Groups. Reported by Google on 2026-06-10 [N/A][546260492] Critical CVE-2026-84352: Use after free in WebGL. Reported by Google on 2026-08-14 [N/A][498839176] High CVE-2026-84354: Incorrect authorization in FileSystem. Reported by Google on 2026-04-02 [N/A][514078656] High CVE-2026-84359: Information leak in Skia. Reported by Google on 2026-05-17 [N/A][523208474] High CVE-2026-84357: Improper input validation in Omnibox. Reported by Google on 2026-06-12 [N/A][533534913] High CVE-2026-84324: Use after free in Proxy. Reported by Google on 2026-07-10 [N/A][537105664] High CVE-2026-84349: Use after free in Browser. Reported by Google on 2026-07-21 [TBD][547936520] High CVE-2026-84326: Uninitialized resource in V8. Reported by Jihyeon Jeong (Compsec Lab, Seoul National University / Research Intern) on 2026-08-17 [N/A][549311485] High CVE-2026-84333: Use after free in Dawn. Reported by Google on 2026-08-19 [TBD][551593376] High CVE-2026-84351: Buffer overflow in GPU. Reported by Cassio Lima on 2026-08-24 [N/A][553117928] High CVE-2026-84325: Improper input validation in DataTransfer. Reported by Google on 2026-08-26 [N/A][498710886] Medium CVE-2026-84328: Missing authorization in FileSystem. Reported by Google on 2026-04-01 [N/A][501679156] Medium CVE-2026-84347: Use after free in WebRTC. Reported by Google on 2026-04-11 [N/A][502411391] Medium CVE-2026-84323: Missing authorization in FileSystem. Reported by Google on 2026-04-14 [N/A][511774376] Medium CVE-2026-84355: Incorrect authorization in Navigation. Reported by Google on 2026-05-10 [N/A][514006886] Medium CVE-2026-84358: Improper privilege management in Downloads. Reported by Google on 2026-05-17 [N/A][514489238] Medium CVE-2026-84332: Incorrect authorization in SiteSettings. Reported by Google on 2026-05-19 [N/A][517091927] Medium CVE-2026-84330: UI misrepresentation in FullScreen. Reported by Google on 2026-05-27 [N/A][517798926] Medium CVE-2026-84334: Incorrect authorization in Chromoting. Reported by Google on 2026-05-29 [N/A][518100026] Medium CVE-2026-84348: Information leak in MediaCapture. Reported by Google on 2026-05-30 [N/A][522302504] Medium CVE-2026-84335: Incorrect authorization in TabStrip. Reported by Google on 2026-06-10 [N/A][498725213] Low CVE-2026-84327: Incorrect authorization in Autofill. Reported by Google on 2026-04-01 [N/A][498850269] Low CVE-2026-84329: Confused deputy in CredentialProvider. Reported by Google on 2026-04-02 [TBD][503787232] Low CVE-2026-84356: UI misrepresentation in FullScreen. Reported by Francesco Topol (k4tedu) on 2026-04-18 [N/A][513713427] Low CVE-2026-84350: Use after free in TabStrip. Reported by Google on 2026-05-16 [N/A][521753402] Low CVE-2026-84331: Incorrect authorization in Actor. Reported by Google on 2026-06-09 We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel. Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL. Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues. Srinivas Sista Google Chrome