Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Chrome Zero-Day CVE-2026-7948: Windows Chromoting Flaw Lets Attackers Gain SYSTEM Access
Google and the Chromium project disclosed CVE-2026-7948 on May 6, 2026, a dangerous vulnerability that demands immediate attention from Windows Chrome users. The flaw, a race condition in the...
CVE-2026-7947 Chrome 148 Update: Windows Users Must Patch UI Spoofing Bug Now
Google silently pushed a critical patch to the Chrome stable channel on May 6, 2026, fixing CVE-2026-7947, a medium-severity user interface (UI) spoofing bug in the Chromium Network component. The...
CVE-2026-7949 Skia Bug: Update Chrome/Edge to Stop Extension Data Leaks
Google and Microsoft disclosed CVE-2026-7949 on May 6, 2026, a medium‑severity Chromium vulnerability in the Skia graphics library that permits cross‑origin data leaks when attacker‑controlled...
Google and Microsoft Rush Patch for Medium-Severity Chromium GFX Memory Bug CVE-2026-7950
Google and Microsoft have issued coordinated disclosures for a medium-severity vulnerability in the Chromium graphics engine, tracked as CVE-2026-7950. The flaw, described as a memory bug in the GFX...
Patch Chrome/Edge Now: CVE-2026-7951 WebRTC Bug Enables Remote Code Execution
Google and Microsoft rushed patches in early May 2026 for a medium-severity vulnerability in WebRTC that allowed remote code execution via a malicious HTML page. CVE-2026-7951, an out-of-bounds write...
Chrome 148 Patches CVE-2026-7952: Malicious Extensions Bypass Policy in Edge, Others
Google shipped an urgent update for Chrome on May 6, 2026, patching CVE-2026-7952, a medium-severity flaw that undermined extension policy enforcement across all Chromium-based browsers. The...
Chrome 148 Patches High-Severity Omnibox UXSS; Edge Fix Coming
CVE-2026-7953, a high-severity universal cross-site scripting (UXSS) flaw in Chromium’s Omnibox, was patched on May 6, 2026, with the release of Google Chrome 148. The vulnerability allows...
Chrome 148 and Edge 148 Patch CVE-2026-7954: Fix for Shared Storage Race Condition
Google and Microsoft released emergency patches the first week of May 2026 to close a race condition in Chromium’s Shared Storage subsystem, tracked as CVE-2026-7954. Chrome desktop moved to...
CVE-2026-7955: Chromium GPU Info Leak Threatens Edge Users – Patch Now
Google and Microsoft jointly disclosed CVE-2026-7955 on May 6, 2026, marking yet another Chrome-derived flaw now tracked in Microsoft Edge. The vulnerability, a medium-severity information leak in...
Update Chrome and Edge now: Patch fixes Chromium media OOB write flaw
Google Chrome has addressed a medium-severity out-of-bounds write vulnerability tracked as CVE-2026-7957, disclosed on May 6, 2026. The flaw resides in the Chromium Media component and affects Chrome...
Chrome Navigation Use-After-Free Flaw Demands Immediate Windows Update
Google pushed out an urgent Chrome update on May 6, 2026, patching a use-after-free vulnerability in the browser’s Navigation component that carries a tangible risk of sandbox escape. Tracked as...
Chrome 148 Patches CVE-2026-7958 UXSS via ServiceWorker Abuse
Google has assigned CVE-2026-7958 to a medium-severity vulnerability in Chrome’s ServiceWorker implementation, patched in the latest stable channel update to version 148.0.7778.96 released on May...