Chrome Security
The latest Chrome Security coverage — news, analysis, and updates from the WindowsNews.AI desk.
Google Chrome 150 Patches Skia Memory Leak—Update Now to Block Data Theft
Google released a desktop update for Chrome on June 30, 2026, fixing a medium-severity memory initialization flaw in the Skia graphics engine tracked as CVE-2026-13971. The vulnerability, present in...
Chrome 150 Update Patches Password UI Spoofing Flaw—Check Your Browser Now
Google pushed a stable channel update for Chrome on March 15, closing a medium-severity security hole that allowed an attacker to spoof the browser’s built-in password manager interface. The fix...
Google Patches Chrome TabStrip UI Spoofing Bug (CVE-2026-13984) – Windows Users Should Update Now
Google shipped an emergency update for Chrome on June 30, 2026, patching a medium-severity vulnerability that could allow remote attackers to spoof the browser’s tab strip and security indicators....
Google Patches Chrome on Windows to Fix DataTransfer Vulnerability That Could Enable UI Spoofing
Google released an update for Chrome on Windows on June 30, 2026, patching a medium-severity security flaw tracked as CVE-2026-13990. The vulnerability, found in the browser’s DataTransfer API,...
Google Fixes Chrome Vulnerability That Allowed Attackers to Spoof Web App Origins
Google disclosed on June 30, 2026, that it had patched a medium‑severity flaw in Chrome’s Web App Install interface, tracked as CVE‑2026‑13993. The bug could let a remote attacker craft a...
Chrome 150 Ships Fix for UI Spoofing Flaw That Could Trick Users Into Granting Permissions
Google released an urgent Chrome update on June 30, 2026, plugging a permissions UI spoofing hole that attackers could exploit to silently hijack camera, microphone, or location access. The stable...
Google Fixes Chrome SanitizerAPI Flaw That Allowed Attackers to Snoop Across Websites
Google released Chrome version 150.0.7871 with a fix for CVE-2026-14023, a vulnerability in the SanitizerAPI that an attacker could exploit to bypass same-origin restrictions. The company rated the...
Google Fixes Chrome Use-After-Free on macOS — Why the Same Update Matters for Windows
On June 30, 2026, Google pushed Chrome version 150.0.7871.47 to the stable desktop channel, patching a use-after-free vulnerability in the browser’s Views framework that specifically affects macOS....
Google Ships Fix for Chrome Parser Flaw That Let Attackers Skirt Webpage Defenses
Google has patched a low‑severity vulnerability in Chrome’s HTML parser that could allow an attacker to bypass Content Security Policy (CSP) protections on any website. The fix, tracked as...
Google Issues Fix for WebProtect Use-After-Free Flaw in Chrome 150
Google on June 30, 2026 disclosed a low-severity use-after-free vulnerability in Chrome’s WebProtect component, tracked as CVE-2026-14111. The bug, which required an attacker to persuade a user...
Chrome 150 Patches Low-Severity Flaw That Could Leak Sensitive Data via DevTools
Google shipped Chrome 150.0.7871.47 to the stable channel on June 30, 2026, patching a low-severity vulnerability that could let a remote attacker steal cross-origin data if a user inspects a...
CVE-2026-14120: Chrome 150 Fixes DevTools Sandbox Escape
Google shipped Chrome 150 with a critical patch on June 30, 2026, closing a high-severity DevTools vulnerability that could allow attackers to escape the browser’s protective sandbox after...