Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerabilityproof-of-concept-release

Google Chrome 148 fixes 127 flaws, including critical Blink and use-after-free bugs

Updated 2mo agoFirst seen May 7, 202615 sources

Google has released Chrome 148 to the stable channel for Windows, macOS, Linux, and Android, patching 127 security vulnerabilities in one of the browser’s largest security update batches. The release fixes three Critical flaws: CVE-2026-7896, an integer overflow in Blink that could lead to heap corruption via a crafted HTML page, plus CVE-2026-7897 and CVE-2026-7898, two use-after-free bugs affecting Mobile and Chromoting. Google said no active exploitation had been reported at release, but urged users to update to 148.0.7778.96/97 immediately; Canada’s cyber agency also advised administrators to apply the update for affected desktop versions prior to those builds.

The advisory also covers more than two dozen high-severity issues across major Chromium components including V8, ANGLE, WebRTC, GPU, Skia, UI, DevTools, Printing, Audio, ChromeDriver, and AdFilter, many involving memory-safety errors such as use-after-free, type confusion, out-of-bounds access, and insufficient validation of untrusted input. Public CVE records tied to the release include CVE-2026-7987, CVE-2026-7988, CVE-2026-7991, CVE-2026-7992, CVE-2026-7995, CVE-2026-8000, CVE-2026-8001, CVE-2026-8002, CVE-2026-8016, and CVE-2026-8018, several of which could enable code execution inside Chrome’s sandbox or, in some cases, potential sandbox escape. Google credited internal testing tools such as fuzzers and sanitizers along with external researchers, paid at least $138,000 in bug bounties, and withheld details for some issues until most users receive fixes; because the bugs affect Chromium, downstream browsers and enterprise Chromium deployments may also need corresponding updates.

Share:
Google Chrome 148 fixes 127 flaws, including critical Blink and use-after-free bugs
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
May 7, 20262mo ago

Google promotes Chrome 148 stable release across desktop platforms

Reporting on the rollout emphasized that Chrome 148 was one of the browser's largest recent security releases, with 127 fixes spanning Critical, High, Medium, and Low severity issues. Google said no active exploitation had been reported at release time and urged immediate updating across Windows, macOS, Linux, and Chromium-based environments.

May 6, 20262mo ago

NVD/CVE records are updated for Chrome 148 vulnerabilities

Multiple CVE records tied to the Chrome 148 release were analyzed or updated with descriptions, affected platforms, CWE classifications, CVSS scores, and references to Google's advisory and Chromium issue tracker entries. These updates included flaws such as CVE-2026-7987, CVE-2026-7988, CVE-2026-7991, CVE-2026-7992, CVE-2026-7995, CVE-2026-8000, CVE-2026-8001, CVE-2026-8002, CVE-2026-8016, and CVE-2026-8018.

Canadian Centre for Cyber Security issues advisory AV26-426

The Canadian Centre for Cyber Security published advisory AV26-426 warning that Chrome versions prior to 148.0.7778.96/97 were affected and urging users and administrators to apply Google's updates. The notice referenced Google's May 5 security advisory for Stable Channel Chrome for Desktop.

May 5, 20262mo ago

Google withholds details for some Chrome 148 flaws pending patch adoption

As part of the Chrome 148 release, Google said technical details for 21 vulnerabilities would remain restricted until a majority of users had updated. The release also credited external researchers and noted bug bounty payouts tied to the disclosed flaws.

Google publishes Chrome 148 stable desktop security update

Google published the Chrome 148 stable channel update for desktop, releasing version 148.0.7778.96 for Linux and 148.0.7778.96/97 for Windows and Mac. The advisory disclosed 127 security fixes, including three critical vulnerabilities affecting Blink, Mobile, and Chromoting.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Google Chrome 148 fixes 127 flaws, including critical Blink and use-after-free bugs | Mallory