Google Chrome: 25 Vulnerabilities Including Critical Flaws Disclosed Together
Key findings • Google Chrome: 25 vulnerabilities disclosed on September 15, 2026, patched in version 153.0.8010.47. • Two Critical (9.6) and numerous High severity flaws, including use-after-…

Key findings
- Google Chrome: 25 vulnerabilities disclosed on September 15, 2026, patched in version 153.0.8010.47.
- Two Critical (9.6) and numerous High severity flaws, including use-after-free, type confusion, and integer overflows.
- Vulnerabilities affect core components like V8, Skia, Workers, Extensions, and PDF handling.
- Exploitation could lead to arbitrary code execution inside or outside the sandbox.
- Users urged to update immediately to the latest version to mitigate risks.
On September 15, 2026, Google released an emergency patch for Chrome, addressing a staggering 25 vulnerabilities disclosed on the same day. The vulnerabilities, ranging in severity from Low to Critical, with two rated Critical (CVSSv3 9.6) and numerous Highs (up to CVSSv3 8.8), underscore the persistent security challenges in complex software like modern web browsers. The swift patching indicates Google's proactive stance in mitigating potential widespread exploitation.
The disclosed vulnerabilities span a variety of components and bug classes within Chrome. Several critical and high-severity flaws were identified in core components such as V8 (CVE-2026-91745, CVE-2026-91721), Skia (CVE-2026-91747, CVE-2026-91740, CVE-2026-91733), and various subsystems like Workers (CVE-2026-91749), Extensions (CVE-2026-91748, CVE-2026-91727), and PDF handling (CVE-2026-91737). These vulnerabilities include use-after-free, type confusion, integer overflows, race conditions, and improper input validation, many of which could lead to arbitrary code execution within the browser's sandbox or even outside of it.
Specific vulnerabilities of note include CVE-2026-91749, a critical use-after-free in Workers, and CVE-2026-91728, a critical integer overflow in V8, both allowing remote attackers to potentially execute arbitrary code. High-severity flaws like CVE-2026-91748 (Race condition in Extensions) and CVE-2026-91736 (Use after free in DOM) also present significant risks, with some requiring social engineering or prior renderer process compromise to exploit. The batch also included vulnerabilities affecting specific platforms, such as Mac (CVE-2026-91748, CVE-2026-91727), Windows (CVE-2026-91734), iOS (CVE-2026-91742), and Android (CVE-2026-91726).
The impact of these vulnerabilities, if left unpatched, could be severe. Attackers could potentially gain control of a user's system, steal sensitive information, or disrupt browser functionality. While the provided information does not detail specific threat actors or in-the-wild exploitation campaigns related to this batch, the sheer number and severity of the disclosed flaws suggest a high potential for exploitation by various malicious actors. The common theme across many descriptions is the possibility of remote attackers executing arbitrary code, often requiring only a crafted HTML page or social engineering.
Google addressed all 25 vulnerabilities in Chrome version 153.0.8010.47. Users are strongly advised to update their Chrome browsers immediately to this version or later to protect themselves from these newly disclosed security risks. The rapid disclosure and patching cycle highlights the ongoing cat-and-mouse game between browser vendors and security researchers/attackers.
This extensive batch of vulnerabilities serves as a critical reminder for Chrome users to maintain up-to-date software. The browser's complexity means that even with robust security measures, flaws can emerge. Staying vigilant and applying patches promptly is the most effective defense against the ever-evolving threat landscape. The coordinated disclosure of these CVEs on a single day suggests a significant security audit or bug bounty payout event, emphasizing the importance of continuous security testing and rapid response.