Google Chrome: 26 Vulnerabilities Patched, Including Two Critical Flaws
Google Chrome 152.0.7977.75 addresses 26 vulnerabilities, including two critical use-after-free flaws in Shared Tab Groups and WebGL, disclosed on September 2, 2026.

Key findings
- Google Chrome 152.0.7977.75 patches 26 vulnerabilities disclosed on September 2, 2026.
- Two critical use-after-free vulnerabilities (CVE-2026-84353, CVE-2026-84352) affect Shared Tab Groups and WebGL.
- High-severity flaws include information leaks, arbitrary code execution, and policy bypasses.
- The update addresses a wide range of bug classes including incorrect authorization and buffer overflows.
- Prompt patching is essential as critical memory-safety vulnerabilities could lead to browser compromise.
On September 2, 2026, Google released an urgent update for its Chrome browser, version 152.0.7977.75, to address a significant batch of 26 vulnerabilities. This disclosure event includes two critical flaws, several high-severity issues, and a mix of medium and low-severity bugs, impacting various components of the browser across different operating systems. The prompt patching of these vulnerabilities is crucial for users to protect themselves against potential exploitation.
The vulnerabilities span a range of common bug classes, including use-after-free, incorrect authorization, information leaks, improper input validation, UI misrepresentation, buffer overflows, and uninitialized resources.
Two critical vulnerabilities, CVE-2026-84353 and CVE-2026-84352, are use-after-free flaws affecting Shared Tab Groups and WebGL respectively. These critical issues, particularly on Android, could allow remote attackers to execute arbitrary code outside the sandbox via crafted HTML pages or UI interaction.
High-severity vulnerabilities include CVE-2026-84359 (Information leak in Skia), CVE-2026-84357 (Improper input validation in Omnibox), CVE-2026-84354 (Incorrect authorization in FileSystem), CVE-2026-84351 (Buffer overflow in GPU on Windows), CVE-2026-84349 (Use after free in Browser), and CVE-2026-84326 (Uninitialized resource in V8). These flaws could lead to information disclosure, arbitrary code execution, or bypassing security policies.
Medium and low-severity vulnerabilities, such as CVE-2026-84358 (Improper privilege management in Downloads), CVE-2026-84355 (Incorrect authorization in Navigation), CVE-2026-84350 (Use after free in TabStrip), and CVE-2026-84324 (Use after free in Proxy), also contribute to the overall risk profile, potentially enabling address bar spoofing, policy bypass, or sensitive information leakage.
Google's official advisory indicates that only three of the 26 reported vulnerabilities were disclosed by external researchers, with no bug bounty rewards publicly disclosed for this batch. While Google has not confirmed any active exploitation in the wild for this specific set of vulnerabilities, the presence of critical and high-severity flaws necessitates immediate action from users.
The update to Chrome 152.0.7977.75 addresses all 26 disclosed vulnerabilities. Users are strongly advised to ensure their Chrome browsers are updated to the latest version to mitigate the risks associated with these security defects. The gradual rollout of the update means users should check their browser settings for the latest available version.
This coordinated disclosure highlights the ongoing efforts by Google to maintain the security of its widely used browser. Users should remain vigilant and apply updates promptly, as attackers continually seek to exploit newly discovered vulnerabilities in popular software.
The patched vulnerabilities include: CVE-2026-84359, CVE-2026-84358, CVE-2026-84357, CVE-2026-84356, CVE-2026-84355, CVE-2026-84354, CVE-2026-84353, CVE-2026-84352, CVE-2026-84351, CVE-2026-84350, CVE-2026-84349, CVE-2026-84348, CVE-2026-84347, CVE-2026-84335, CVE-2026-84334, CVE-2026-84333, CVE-2026-84332, CVE-2026-84331, CVE-2026-84330, CVE-2026-84329, CVE-2026-84328, CVE-2026-84327, CVE-2026-84326, CVE-2026-84325, CVE-2026-84324.