VYPR
Vypr IntelligenceAI-generatedAug 25, 2026· 25 CVEs

Chromium: 25 Vulnerabilities Disclosed Together, Including Critical Use-After-Free Flaws

Google Chrome 152.0.7977.65 addresses a batch of 25 vulnerabilities, including critical flaws allowing code execution and information leaks.

Key findings

  • 25 CVEs disclosed for Google Chrome on August 25, 2026, all fixed in version 152.0.7977.65.
  • Critical vulnerabilities include multiple 'use after free' flaws allowing arbitrary code execution.
  • Several vulnerabilities permit attackers to leak sensitive information or bypass security policies.
  • The batch includes issues in components like Animation, Aura, Workers, and Extensions.
  • Users are urged to update to Chrome 152.0.7977.65 to patch these vulnerabilities.

On August 25, 2026, a significant batch of 25 vulnerabilities was disclosed for Google Chrome, all addressed in version 152.0.7977.65. This coordinated disclosure event highlights ongoing security challenges within the widely used browser, with vulnerabilities spanning various components and impact levels, including critical flaws that could lead to arbitrary code execution.

Several vulnerabilities stem from memory-safety issues. Notably, multiple "use after free" bugs were identified: CVE-2026-79290 and CVE-2026-79232, both rated Critical, allow remote attackers to execute arbitrary code outside the sandbox. CVE-2026-79248, a High-severity flaw in Chromoting, also involves a use-after-free vulnerability enabling code execution. Other memory-related issues include CVE-2026-79244 (Integer overflow, High severity) and CVE-2026-79223 (Uninitialized resource, Medium severity), which could allow attackers to read memory within the sandbox.

Information disclosure remains a concern, with several CVEs detailing how remote attackers could obtain sensitive data. CVE-2026-79293 (Medium severity) is an information leak in Animation, while CVE-2026-79287 (Medium severity) involves an observable discrepancy in Forms. CVE-2026-79265 (Medium severity) in GetUserMedia, and CVE-2026-79258 (Medium severity) in WebXR, also present risks of sensitive data exposure, with the latter requiring social engineering. Additionally, CVE-2026-79252 (Medium severity) in ServiceWorker and CVE-2026-79234 (Medium severity) in CSS relate to information leaks or potential sensitive data exposure.

Vulnerabilities related to authorization and policy bypass were also prominent. CVE-2026-79260 (Medium severity) in Cookies, CVE-2026-79248 (Medium severity) in Input, and CVE-2026-79237 (Medium severity) in Navigation, all involve improper authorization that could lead to bypassing web origin policies. CVE-2026-79267 (Medium severity) in Workers exploits a race condition to bypass web origin policy, and CVE-2026-79289 (Low severity) in Workers allows bypassing site isolation.

The batch also includes vulnerabilities affecting specific components like Workers, Animation, Aura, and Extensions. CVE-2026-79263 (High severity) involves a race condition in Extensions, potentially allowing arbitrary code execution. CVE-2026-79245 (High severity) is a use-after-free in UI, and CVE-2026-79242 (High severity) is a use-after-free in Animation, both allowing code execution. CVE-2026-79232 (Critical severity) is a use-after-free in Aura.

Google Chrome version 152.0.7977.65 addresses all these vulnerabilities. Users are strongly advised to update to this version to mitigate the risks associated with these flaws. The timely patching of these numerous issues underscores the continuous effort required to maintain the security of widely used software like Chrome.

This coordinated disclosure of 25 CVEs highlights the persistent threat landscape facing web browsers. The variety of vulnerabilities, from critical memory-safety issues to information leaks and authorization bypasses, necessitates ongoing vigilance from users and developers alike. Staying updated with the latest browser versions remains the most effective defense against such widespread security threats. The release of Chrome 152, which includes these fixes, is a critical step in protecting users from potential exploitation.

AI-written article. Grounded in 25 CVE records listed below.