HomeinetGoogle Chrome update fixes 21 vulnerabilities

Google Chrome update fixes 21 vulnerabilities

Google has released an update for Stable Channel , addressing 21 security vulnerabilities, including a high-profile malicious code injection vulnerability that is being actively exploited online. The update was released Wednesday evening. Among the 21 security vulnerabilities fixed in this update, one in particular has drawn attention: a malicious code injection vulnerability that allows attackers to inject malicious code into Chrome users' systems.

See also: New zero-day threat in Chrome: Urgent intervention from Google

Google updates

Google has confirmed that this vulnerability is currently being targeted by malicious actors, making the update extremely urgent for both individual users and organizations.

The company noted that of the 21 vulnerabilities, 19 are classified as high risk, while two are considered medium severity. The awareness of active exploitation on the Internet highlights the importance of installing the latest Stable Channel update as soon as possible. According to Google's official announcement, the new Stable Channel update includes: Version 146.0.7680.177/178 for Windows and Mac Version 146.0.7680.177 for Linux. The release is expected to take place in the coming days and weeks, depending on user settings and regional distributions.

Google has provided a detailed changelog that lists all the security vulnerabilities fixed in this update, although access to some bug details may remain limited until the majority of users have installed the fix. This precautionary measure is designed to prevent the exploitation of vulnerabilities in third-party libraries that are also used by other projects.

The update addresses multiple high-risk vulnerabilities reported by security researchers between March 1 and March 25, 2026.

See also: GlassWorm malware hides RAT in Chrome extension

Google Chrome update fixes 21 vulnerabilities

Some of the most notable include:

  • CVE-2026-5273: Use-after-free in CSS, reported on March 18
  • CVE-2026-5272: GPU buffer overflow, reported on March 11
  • CVE-2026-5274: Integer overflow in Codecs, reported on March 1
  • CVE-2026-5281: Use-after-free in Dawn, reported on March 10 (actively exploited online)
  • CVE-2026-5287: Use-after-free in PDF, reported on March 21

Other vulnerabilities addressed involve ANGLE, WebUSB, WebCodecs, WebGL, WebView, V8 , and multiple components of Chrome's rendering engine.

Google acknowledged the ongoing threat posed by the malicious code injection vulnerability, noting that CVE-2026-5281 is actively being exploited. The company also thanked security researchers who worked to identify and report these issues, citing tools such as AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer , and AFL as key tools in detecting and mitigating these security vulnerabilities before they reach the stable channel.

By publicly disclosing these vulnerabilities, Google aims to provide transparency while allowing users and organizations to patch their systems immediately. This Stable Channel update highlights the ongoing risks posed by security vulnerabilities in widely used software like Chrome.

See also: VoidStealer malware steals passwords – Chrome ABE bypass

chrome

Users are strongly encouraged to install the latest Chrome update on all devices to reduce exposure to these threats. Regularly updating browsers remains one of the most effective defenses against cyberattacks targeting widely deployed software.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS