Chrome 152 Ships 327 Security Fixes, 10 Critical Flaws

Google has released Chrome 152 for Windows, macOS, and Linux, delivering a sweeping security update that fixes 327 vulnerabilities in a single stable-channel release[1][2][4]. The browser is rolling out as version 152.0.7977.64 for Linux and 152.0.7977.64/.65 for Windows and macOS, expanding on earlier reports that the update would address “over 300” flaws[1][2][10].

SecurityWeek reports that ten of the vulnerabilities in Chrome 152 are rated critical, with many classified as use-after-free bugs in components such as Angle, Aura, Chromecast, Views, and SafeBrowsing[10]. An additional 61 flaws are rated high severity, while the rest fall into medium and low categories, underscoring that the release is primarily a large-scale clean-up of memory safety issues rather than a handful of isolated defects[10]. According to Google’s disclosure, the majority of these vulnerabilities were found internally using AI-powered analysis and fuzzing, reflecting the company’s growing reliance on automated systems to surface complex browser bugs before attackers can weaponize them[10].

The stable-channel advisory notes that Chrome 152.0.7977.64/.65 includes numerous security fixes and improvements, with the full technical details listed in the project’s change log referenced from the Chrome Releases blog[1][2][5]. Enterprise-oriented coverage emphasizes that the risk window applies to all Chrome stable installations prior to 152.0.7977.64/.65 on Windows, macOS, and Linux, leaving any lagging endpoints exposed to a large attack surface until they are updated[3]. Extended Stable users are also pulled into this release cycle, as Google’s separate extended-stable notes reference the same version family and security fix count[5].

One of the newly logged Chrome vulnerabilities associated with this release, CVE-2026-79290, is recorded with a critical severity and a 9.6 base score in public CVE tracking, highlighting the potential impact of at least some of the underlying bugs[11]. While detailed technical write-ups for individual CVEs in Chrome 152 are still being surfaced through vulnerability databases and vendor documentation, the combination of high CVSS scores and memory-corruption classes suggests that exploitation could enable remote code execution or sandbox escape in realistic attack chains, especially if combined with other weaknesses in the browser or operating system[10][11].

Neither Google’s stable-channel advisory nor early third-party coverage has yet flagged any of the Chrome 152 vulnerabilities as being exploited in the wild, and there are no widely cited public proof-of-concept exploits tied specifically to this batch at the time of writing[1][4][10]. However, past Chrome security updates have quickly attracted attention from exploit developers and commercial offensive security vendors once technical details became available, and the sheer volume of fixes in 152 will likely incentivize researchers and attackers alike to mine the patch diff for high-value bugs[4][10]. The fact that many of the issues were only discovered internally via AI-backed tooling also underscores that automated analysis is surfacing weaknesses that traditional manual research might miss, which could reshape how browser exploit markets evolve[10].

For defenders, the practical guidance is straightforward but urgent: organizations should prioritize rolling out Chrome 152.0.7977.64/.65 across all supported desktop platforms and enforce a browser restart, as the new version’s protections do not fully apply until Chrome is relaunched[1][3]. Enterprise-focused advisories recommend forcing updates via endpoint management tools and auditing fleets to confirm that older builds are not lingering, particularly on high-risk user segments such as developers, administrators, and staff with broad internet access[3][4]. Given the number of critical and high-severity vulnerabilities closed in this release and Google’s explicit reliance on AI to surface them, deferring patching effectively cedes the advantage to attackers who now know precisely which weaknesses have been removed from the browser[1][4][10].

References

  1. Chrome Releases: Stable Channel Update for Desktop
  2. Chrome Releases: 2026
  3. Chrome 152 Stable Channel Update: 327 Security Fixes
  4. Google Chrome 152 Released With 327 Security Fixes, Including 10 Critical Vulnerabilities
  5. Extended Stable updates – Google Chrome Releases
  6. Chrome 152 Patches Over 300 Vulnerabilities
  7. Chrome CVEs and Security Vulnerabilities – OpenCVE

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply