Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Patch Chrome 148 Now: V8 Memory Leak Bug Lets Attackers Exploit Crafted HTML
Google and Microsoft jointly disclosed CVE-2026-7936 on May 6, 2026, a medium-severity object lifecycle flaw in Chromium’s V8 JavaScript engine that enables out-of-bounds memory reads through...
Chrome 148 & Edge 148 Patch Critical Popup Blocker Bypass Flaw
Google and Microsoft have rushed out fixes for CVE-2026-7934, a medium-severity flaw in Chromium’s popup blocker that could allow malicious websites to bypass one of the browser’s oldest...
CVE-2026-7935: Chrome UI Spoofing via Speech Component Fixed in Version 148+
Google has patched a medium-severity vulnerability in Chrome's Speech component that could allow attackers to spoof the browser's user interface. The flaw, tracked as CVE-2026-7935, was disclosed on...
Chrome 148 Fixes CVE-2026-7937: Why This Medium Bug Matters for Edge Too
On May 6, 2026, Google and Microsoft jointly disclosed CVE-2026-7937, a medium-severity flaw in Chromium’s DevTools policy enforcement that, before Chrome 148.0.7778.96, allowed a malicious...
Google Patches Critical Chrome UXSS Bug Allowing Script/HTML Injection
Google has assigned CVE-2026-7939 to a freshly patched universal cross-site scripting (UXSS) vulnerability in Chrome’s built‑in Sanitizer API. The medium‑severity flaw, disclosed on May 6,...
CVE-2026-7938: Critical Chromium Use-After-Free Bug Forces Emergency Chrome and Edge Updates
Google and Microsoft are urging immediate browser updates to patch CVE-2026-7938, a high-severity use-after-free vulnerability in Chromium's Cascading Style Sheets (CSS) engine that could allow...
Chrome V8 CVE-2026-7940: Patch Now to Block Malicious Extensions
Google and Microsoft jointly disclosed CVE-2026-7940 on May 6, 2026, a medium-severity vulnerability in the V8 JavaScript engine that underpins Chromium-based browsers. The flaw, which affects Google...
Chrome 148 Fixes Critical ANGLE Flaw Leaking Cross-Origin Data via WebGL
Google on May 6, 2026, disclosed a detail-drenched security advisory for CVE-2026-7942, a medium-severity integer overflow bug in the Almost Native Graphics Layer Engine (ANGLE) used by Chromium. The...
CVE-2026-7943: Patch Chrome and Edge Now for Critical ANGLE Memory Bug
{ "title": "CVE-2026-7943 ANGLE Read/Write Bug: Chrome and Edge Patch Guidance for Windows", "content": "Google and Microsoft rushed out patches for a potentially devastating vulnerability in the...
CVE-2026-7944: Urgent Chrome 148 & Edge Patch for Cache Data Theft Risk
Google and Microsoft have disclosed a critical security flaw in the Chromium browser engine on May 6, 2026. The vulnerability, tracked as CVE-2026-7944, affects the Persistent Cache system in Google...
Chrome 148 Patches CVE-2026-7945 COOP Flaw Bypassing Site Isolation
Google and Microsoft jointly disclosed CVE-2026-7945 on May 6, 2026, a medium-severity vulnerability in Chromium’s handling of the Cross-Origin-Opener-Policy (COOP) that puts site isolation at...
Patch Chrome 148 Now: Critical Site Isolation Bypass Exposes Windows Users
Google and Microsoft disclosed CVE-2026-7946 on May 6, 2026, a medium-severity vulnerability in Chromium that could let a compromised renderer process bypass site isolation. The flaw affects all...