Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-software-vulnerabilitywidely-deployed-product-advisoryidentity-authentication-vulnerability

Google Patches Seven Critical Chrome RCE Flaws in Stable Update

Updated 16h agoFirst seen Jun 17, 20268 sources

Google released a Chrome Stable channel update to fix 33 vulnerabilities, including seven Critical flaws that could allow remote code execution if a user visits a malicious webpage. The update moves Chrome to 149.0.7827.155/.156 on Windows and macOS and 149.0.7827.155 on Linux, with Google rolling it out gradually. The most serious issues are largely use-after-free memory corruption bugs affecting components including WebShare, Digital Credentials, File Input, Passwords, and Web Authentication.

Named issues include CVE-2026-12437 in WebShare, CVE-2026-12439 and CVE-2026-12440 in Digital Credentials, CVE-2026-12442 in Passwords, and CVE-2026-12443 in Web Authentication. Google also patched High-severity flaws in WebRTC, Extensions, Safe Browsing, GPU, File System Access, Media, Downloads, and the Tab Strip, with risks ranging from data leakage and heap corruption to sandbox escape and exploit chaining. The company said technical details will remain limited until more users update and urged users and enterprises to install the patch and relaunch Chrome promptly.

Share:
Google Patches Seven Critical Chrome RCE Flaws in Stable Update
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

3 events from the most recent confirmed update back to the earliest known activity.

3 EVENTS
Jun 18, 20265d ago

Debian publishes DSA 6351-1 Chromium security update

Debian issued security advisory DSA 6351-1 for Chromium. This is a separate downstream vendor security update from the previously listed Google Chrome and Mozilla Firefox releases.

[SECURITY] [DSA 6351-1] chromium security update
Jun 17, 20266d ago

Mozilla releases Firefox 152 security updates fixing 40 vulnerabilities

Mozilla released Firefox 152 security updates on June 17, 2026, fixing 40 vulnerabilities, including 13 high-severity flaws such as use-after-free, privilege escalation, sandbox escape, JIT miscompilation, and other memory safety bugs. Mozilla also issued related updates for Firefox ESR, Thunderbird, and Firefox for iOS.

Chrome and Firefox Updated to Patch Critical, High-Severity Vulnerabilities - SecurityWeek

Google releases Chrome 149 security update fixing 33 vulnerabilities

Google released a Chrome Stable channel security update that fixes 33 vulnerabilities, including seven critical flaws that could enable remote code execution. The update advances Chrome to version 149.0.7827.155/.156 on Windows and macOS and 149.0.7827.155 on Linux, with rollout beginning gradually.

Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now!
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

40 LINKEDOpen in app
Vulnerabilities
33 linked
Use-after-free in Web Authentication in Google ChromeUse-after-free in Google Chrome Digital CredentialsUse-after-free in Passwords in Google Chrome on AndroidUse-after-free in DigitalCredentials in Google ChromeUse-after-free in WebShare in Google Chrome on WindowsUse-after-free in Google Chrome Tab StripPrivilege Escalation in WebView in Google Chrome on AndroidSite Isolation Bypass in Google Chrome ExtensionsUXSS in Google Chrome SerialUse-after-free in Downloads in Google Chrome on AndroidOut-of-bounds Read in Google Chrome ChromotingSite Isolation Bypass in Google Chrome File System AccessUse-after-free in Media in Google ChromeSame Origin Policy Bypass in Google Chrome InputSame Origin Policy Bypass in Google Chrome ExtensionsHeap Buffer Overflow in WebRTC in Google ChromeSandbox escape use-after-free in Google Chrome ExtensionsSandbox Escape Race Condition in Google Chrome Safe Browsing on MacCross-origin data leak via uninitialized GPU use in Google Chrome on AndroidOut-of-bounds read in WebRTC in Google Chrome on WindowsUse-after-free in Chromoting in Google Chrome for WindowsSandbox Escape in WebView in Google Chrome on AndroidCross-origin data leak in Google Chrome PasswordsUse-after-free sandbox escape in Google Chrome BrowserSandbox escape race condition in Google Chrome Updater on macOSUXSS in Google Chrome Views on LinuxSandbox escape in Google Chrome MetricsUse-after-free in Google Chrome ExtensionsHeap Buffer Overflow in WebRTC in Google Chrome on WindowsUse-after-free in File Input in Google Chrome on LinuxCross-origin data leak via incorrect security UI in Chrome PasswordsSensitive information disclosure in Google Chrome MediaUse-after-free in Google Chrome DigitalCredentials sandbox escape
Affected products
3 linked
Firefox For IosFirefox EsrChromium
Organizations
4 linked
GoogleMozillaSecurityWeekSecurityOnline.info
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Google Patches Seven Critical Chrome RCE Flaws in Stable Update | Mallory