Critical Chrome vulnerabilities could allow remote code execution attacks
Google has released a new Chrome security update that fixes 16 vulnerabilities, including two Critical flaws that could expose users to remote code execution and browser spoofing risks.
The Chrome Stable channel update moves the browser to version 148.0.7778.178/179 for Windows and Mac, and 148.0.7778.178 for Linux. Google said the update will roll out over the coming days and weeks.
Access content across the globe at the highest speed rate.
70% of our readers choose Private Internet Access
70% of our readers choose ExpressVPN
Browse the web from multiple devices with industry-standard security protocols.
Faster dedicated servers for specific actions (currently at summer discounts)
Users should update Chrome as soon as possible and restart the browser after the update installs. Browser flaws can be especially risky because attackers may only need to lure a victim to a malicious or compromised web page.
Two critical Chrome flaws were patched
The most serious issue is CVE-2026-9111, a use-after-free flaw in WebRTC. The National Vulnerability Database describes it as a vulnerability that allowed a remote attacker to execute arbitrary code through a crafted HTML page in affected Chrome versions.
The second Critical issue is CVE-2026-9110, an inappropriate implementation flaw in Chrome’s UI layer. Google reported both Critical issues internally on April 20, 2026, according to the Chrome release notes.
Use-after-free vulnerabilities are dangerous because they involve memory that has already been released but can still be accessed incorrectly. In real-world browser attacks, memory corruption bugs can become more serious when chained with other flaws.
| CVE | Severity | Component | Issue type | Reported by |
|---|---|---|---|---|
| CVE-2026-9111 | Critical | WebRTC | Use after free | |
| CVE-2026-9110 | Critical | UI | Inappropriate implementation |
High-severity bugs affect WebRTC, GPU, QUIC, and other components
The update also includes nine High-severity fixes across several Chrome components. These include WebRTC, GPU, QUIC, Service Worker, GFX, and XR.
Several of the High-severity issues involve memory safety problems, including use-after-free flaws, an out-of-bounds read, type confusion, and a heap buffer overflow. These bug classes can create serious security risks if attackers find a reliable exploit path.
Two externally reported GPU flaws received listed bug bounties. CVE-2026-9112, a use-after-free issue in GPU, earned an $11,000 reward, while CVE-2026-9113, an out-of-bounds read in GPU, earned $3,000.
| CVE | Severity | Component | Issue type |
|---|---|---|---|
| CVE-2026-9112 | High | GPU | Use after free |
| CVE-2026-9113 | High | GPU | Out-of-bounds read |
| CVE-2026-9114 | High | QUIC | Use after free |
| CVE-2026-9115 | High | Service Worker | Insufficient policy enforcement |
| CVE-2026-9116 | High | ServiceWorker | Insufficient policy enforcement |
| CVE-2026-9117 | High | GFX | Type confusion |
| CVE-2026-9118 | High | XR | Use after free |
| CVE-2026-9119 | High | WebRTC | Heap buffer overflow |
| CVE-2026-9120 | High | WebRTC | Use after free |
Medium-severity flaws were also fixed
Google also fixed Medium-severity issues in GPU, Chromecast, Input, and DOM. These include out-of-bounds reads, a heap buffer overflow, insufficient validation of untrusted input, and another use-after-free flaw.
The company said access to bug details and links may remain restricted until most users receive the fix. Google also keeps restrictions in place when a bug exists in a third-party library that other projects depend on and may not have fixed yet.
That restriction helps reduce the chance that attackers can use detailed bug information before users and organizations have time to update. The NVD entry for CVE-2026-9111 also confirms the remote attack risk tied to a crafted HTML page.
How to update Chrome now
Chrome usually updates automatically, but users should not wait for the staged rollout if they manage sensitive accounts or business systems. A manual update check can install the patch sooner.
GovCERT.HK also advised users to update Chrome to version 148.0.7778.178 or later and relaunch the browser to make the update effective. The advisory warned that successful exploitation could lead to remote code execution, denial of service, information disclosure, security restriction bypass, or spoofing.
Administrators should check managed endpoints and confirm that the patched Chrome build has reached all Windows, macOS, and Linux systems.
- Open Chrome.
- Click the three-dot menu in the top-right corner.
- Go to Help, then About Google Chrome.
- Wait while Chrome checks for updates.
- Restart the browser when prompted.
- Confirm the version shows 148.0.7778.178 or later.
What enterprise administrators should check
Enterprise teams should treat this as a priority browser update, especially where Chrome handles email, SaaS dashboards, admin portals, finance tools, or remote work platforms.
Admins should enforce Chrome updates through their endpoint management tools and monitor for devices that fail to restart after patch installation. A browser update does not fully apply until Chrome relaunches.
Organizations should also review policies for Chromium-based browsers and confirm that other browsers receive their own vendor updates when corresponding patches become available. The GovCERT.HK security alert recommends updating to the fixed version immediately.
- Force Chrome updates through endpoint management tools.
- Confirm patched versions across Windows, macOS, and Linux devices.
- Require browser relaunch after the update installs.
- Watch for devices that remain below version 148.0.7778.178.
- Review browser security policies for managed users.
- Monitor vendor advisories for Chromium-based browser updates.
FAQ
Google updated Chrome to 148.0.7778.178/179 for Windows and Mac, and 148.0.7778.178 for Linux. Users should install version 148.0.7778.178 or later and restart Chrome.
CVE-2026-9111 is a Critical use-after-free vulnerability in Chrome’s WebRTC component. It could allow a remote attacker to execute arbitrary code through a crafted HTML page in affected Chrome versions.
CVE-2026-9110 is a Critical inappropriate implementation vulnerability in Chrome’s UI component. Google fixed it in the same Stable channel update as CVE-2026-9111.
Open Chrome, click the three-dot menu, choose Help, then About Google Chrome. Chrome will check for updates automatically. Relaunch the browser when prompted to finish the update.
Read our disclosure page to find out how can you help VPNCentral sustain the editorial team Read more
User forum
0 messages