Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Google Patches High-Severity Use-After-Free Flaw in Chrome’s Media Engine on Windows
Google has released an urgent patch for a high-severity use-after-free vulnerability in Chrome’s Media component that exclusively impacts Windows users. Tracked as CVE-2026-12013, the flaw was...
Chrome 149 Patches High-Severity Cast Use-After-Free Bug Exploitable Over LAN
A high-severity use-after-free vulnerability in Google Chrome’s Cast component, tracked as CVE-2026-12014, was published by the National Vulnerability Database on June 11, 2026. The flaw affects...
Chrome 149 Emergency Fix Closes CVE-2026-12017 — High‑Severity Site Isolation Bypass via Extensions
Google shipped Chrome 149.0.7827.114 for Windows and Mac and 149.0.7827.115 for Linux on June 11, 2026, plugging a high‑severity hole that let a compromised renderer slip past Site Isolation by...
Critical Chrome RCE Flaw CVE-2026-12007 Patched: Update Windows Browsers to 149.0.7827.115 Now
Google has rushed out a critical security update for Chrome on Windows, fixing a use-after-free vulnerability that could allow remote code execution. Tracked as CVE-2026-12007, the flaw was patched...
Urgent Chrome Update Closes Mojo Vulnerability That Gives Attackers Windows Admin Rights
Google has disclosed CVE-2026-12018, a high-severity vulnerability in Chrome for Windows that allows a local attacker to escalate privileges to the operating system level. Patched on June 11, 2026,...
High-Severity Autofill Flaw in Chrome 149 Fixed: Update to 149.0.7827.115 Now
Google rolled out an emergency fix for a high-severity use-after-free vulnerability in Chrome’s Autofill component on June 11, 2026. Tracked as CVE-2026-12015, the flaw allows a remote attacker who...
Chrome 149.0.7827.115 Closes DevTools Sandbox Escape That Left Windows Exposed
Google pushed out Chrome 149.0.7827.115 to the stable channel on June 11, 2026, closing a critical sandbox escape vulnerability in the browser’s Developer Tools (DevTools). The patch addresses...
Chrome Patches High-Severity CVE-2026-12019: Heap Overflow Could Allow Sandbox Escape on Linux and ChromeOS
Google has released an urgent update for Chrome on Linux and ChromeOS, patching a high-severity vulnerability that could allow attackers to break out of the browser's protective sandbox and execute...
Google Patches Critical Chrome Use-After-Free Bug Allowing Sandbox Escape on Windows
Google has sealed a critical vulnerability in Chrome that could have let attackers break out of the browser’s sandbox and run malicious code on Windows computers. The flaw, tracked as...
Google Patches High‑Severity Use‑After‑Free Flaw in Chrome’s Network Component (CVE‑2026‑12012)
Google rolled out an urgent stable channel update for Chrome on Windows, macOS, and Linux on June 11, 2026, dismantling a high‑severity use‑after‑free vulnerability that lived inside the...
CVE-2026-34182: OpenSSL Flaw Enables CMS Forgery Attacks, Windows Users Urged to Patch
A severe vulnerability in the OpenSSL cryptographic library surfaced on June 9, 2026, enabling attackers to forge authenticated encrypted messages in the Cryptographic Message Syntax (CMS)...
Urgent Vim Update: Python Omni-Completion Bug (CVE-2026-52858) Allows Code Execution From Hostile Buffers
Vim users worldwide need to update immediately after the disclosure of CVE-2026-52858, a serious vulnerability that lets attackers execute arbitrary code simply by tricking a victim into triggering...