Security Alerts
The latest Security Alerts coverage — news, analysis, and updates from the WindowsNews.AI desk.
Chrome 148 Patch Fixes Critical Site Isolation Bypass for Windows Admins
Google and Microsoft dropped a joint disclosure on May 6, 2026, confirming that Chrome 148 patches CVE-2026-7959, a medium-severity flaw in Chromium’s Navigation component. The vulnerability could...
Chrome 148.0.7778.96 Patches CVE-2026-7960 Speech API Race Condition
Google has issued an update for Chrome that fixes a race condition in the browser’s Speech component, tracked as CVE-2026-7960. The medium-severity flaw could let attackers coax a renderer process...
Patch Chromium Permissions Flaw: Update Chrome 148 and Edge 148 Now
Google released Chrome 148.0.7778.96 for Linux and 148.0.7778.96/97 for Windows and Mac on May 6, 2026, addressing CVE-2026-7961—a medium-severity flaw in the Chromium permissions system. The fix...
Medium Chromium Bug in Edge Exposes Enterprise WebTransport Apps
Microsoft’s security team warned enterprises this week about a newly patched vulnerability in the Chromium engine that powers Microsoft Edge. The bug, tracked as CVE-2026-7962, resides in the...
Update Chrome 148 or Edge Now: CVE-2026-7963 ServiceWorker Sandbox Escape Lets Code Escape Browser
Google released Chrome 148.0.7778.96/97 for Windows and macOS, and 148.0.7778.96 for Linux, on May 6, 2026, addressing a medium-severity security flaw tracked as CVE-2026-7963. The vulnerability...
CVE-2026-7964: Chrome FileSystem Bug Forces Urgent Enterprise Browser Patches
Google and Microsoft simultaneously disclosed CVE-2026-7964 on May 6, 2026, a medium-severity vulnerability in the Chromium FileSystem component that was patched in Google Chrome version...
Chromium DevTools Medium Bug Poses High Risk for Developer Machines
Google and Microsoft issued coordinated disclosures on May 6, 2026, for CVE-2026-7965, a medium-severity input-validation flaw in the DevTools component of Chromium. The bug, fixed in Google Chrome...
Patch Chromium Navigation flaw now: Edge sandbox-escape risk patched
Microsoft has issued a security advisory for a critical Chromium Navigation vulnerability tracked as CVE-2026-7967, which could allow an attacker to escape the browser sandbox and execute arbitrary...
CVE-2026-7966: Update Chrome 148 and Edge 148 Now to Fix Site Isolation Bypass
Google and Microsoft released critical security updates on May 6 and 7, 2026, addressing a high-severity vulnerability in the Chromium engine’s Site Isolation feature. Tracked as CVE-2026-7966, the...
Chrome 148 Patches CVE-2026-7968 CORS Flaw—Windows Users Must Update Now
Google disclosed a medium-severity vulnerability in its Chrome browser on May 6, 2026, that underscores the relentless pace of modern browser exploitation and the critical importance of rapid...
CVE-2026-7969: Patch Chrome/Edge Now for Critical Same-Origin Bypass Risk
Microsoft and Google simultaneously published details of a critical new vulnerability on May 6 and 7, 2026. CVE-2026-7969 allows an attacker who has already compromised a website’s renderer process...
TopChrome UAF in Chrome 148.0.7778.96 — Patch Now for RCE Risk
Google and Microsoft have jointly disclosed a critical use-after-free vulnerability in the Chromium browser engine, tracked as CVE-2026-7970, that affects all Chromium-based browsers including Google...