VYPR
patchPublished Aug 26, 2026· 2 sources

Google Chrome 152 Released With 327 Security Fixes, Including 10 Critical Vulnerabilities

Google Chrome 152 addresses 327 security fixes, including 10 critical vulnerabilities like use-after-free flaws in ANGLE, Aura, and Chromecast.

Google has rolled out Chrome version 152, a significant update that bundles a total of 327 security fixes and enhancements for Windows, macOS, and Linux users. This release is particularly noteworthy for patching 10 critical vulnerabilities, underscoring the importance of immediate updates for both individual users and enterprise environments.

The update, versioned 152.0.7977.64 for Linux and 152.0.7977.64/.65 for Windows and macOS, is gradually being distributed. Google advises users to update promptly to ensure their browsers are protected against newly discovered threats.

A primary focus of this release is the remediation of memory-safety issues, with several critical use-after-free vulnerabilities being addressed. These types of bugs occur when a program attempts to access memory that has already been deallocated, potentially leading to browser crashes, unauthorized access to sensitive data, or even remote code execution within the context of the Chrome process.

Several core Chrome components are affected by these critical flaws. Specifically, CVE-2026-79282 is a use-after-free vulnerability identified in ANGLE, Chrome's graphics translation layer, which was reported by a security researcher who received a $25,000 reward. Other critical vulnerabilities impact Aura, Chrome's user-interface framework, and the Chromecast component, among others.

Additional critical vulnerabilities patched include CVE-2026-79290 and CVE-2026-79052, both use-after-free flaws in Aura. The Chromecast component is further affected by CVE-2026-79054 and CVE-2026-79224, also use-after-free issues, as well as CVE-2026-79121, an improper input validation vulnerability. The update also addresses CVE-2026-79150 (use-after-free in Views), CVE-2026-78935 (use of uninitialized variable in Mobile), CVE-2026-79012 (use-after-free in Safe Browsing), and CVE-2026-79200 (use-after-free in Aura).

Beyond the critical vulnerabilities, Chrome 152 also incorporates a substantial number of high-severity fixes across various subsystems, including ANGLE, WebGL, V8, WebRTC, Extensions, Autofill, GPU, Bluetooth, Sandbox, and Password management. These high-severity bugs encompass a range of issues such as buffer overflows, out-of-bounds reads and writes, type-confusion errors, authorization flaws, race conditions, and information leaks.

While Google has not indicated that any of these vulnerabilities are currently being actively exploited in the wild, the company has temporarily restricted access to detailed bug information and associated links. This measure is standard practice to allow users sufficient time to update before exploit details become widely available, especially when third-party libraries are involved.

Users are strongly urged to update their Google Chrome browsers immediately. This can be done by navigating to the browser's menu, selecting 'Help,' then 'About Google Chrome,' which will automatically check for and download the latest version. Organizations should ensure that managed endpoints are updated through their established update channels as soon as Chrome 152 becomes available.

The latest Chrome update, version 152, addresses a substantial number of vulnerabilities, totaling over 300. While Google's internal AI tools were instrumental in discovering the majority of these flaws, external researchers continue to identify critical issues, with one researcher being awarded $25,000 for a critical vulnerability tracked as CVE-2026-79282. Google's advisory does not indicate any of these vulnerabilities are currently being exploited in the wild.

Synthesized by Vypr AI