Google Chrome Multiple High-Severity Vulnerabilities
Severity Level: High
Date: 28/07/2026
Ref: CERT-NCSOC-0246
Components Affected
- Google Chrome Stable for desktop installations not yet updated to version 150.0.7871.186/.187 on Windows and macOS.
- Google Chrome Stable for Linux installations not yet updated to version 150.0.7871.186.
Overview
On 23 July 2026, Google released a Stable Channel update for Google Chrome on desktop that addresses four High-severity security vulnerabilities.
The vulnerabilities are tracked as CVE-2026-16804, CVE-2026-16805, CVE-2026-16806, and CVE-2026-16807. They include three use-after-free vulnerabilities and one out-of-bounds write vulnerability.
Organizations and users are advised to update affected Google Chrome installations promptly and confirm that the browser has been restarted and is running the fixed version.
Description
Google updated the Chrome Stable Channel to 150.0.7871.186/.187 for Windows and macOS and 150.0.7871.186 for Linux.
The release addresses the following vulnerabilities:
- CVE-2026-16807 – Out-of-bounds write vulnerability in Codecs.
- CVE-2026-16806 – Use-after-free vulnerability in WebMCP.
- CVE-2026-16805 – Use-after-free vulnerability in Blink.
- CVE-2026-16804 – Use-after-free vulnerability in Input.
CVE-2026-16805 and CVE-2026-16806 may allow a remote attacker to execute arbitrary code inside the Chrome sandbox through a crafted HTML page.
CVE-2026-16807 may potentially enable a Chrome sandbox escape through a crafted HTML page, while CVE-2026-16804 may potentially enable a sandbox escape after the renderer process has already been compromised.
Google has restricted access to detailed bug information until a majority of users have received the fixes. The vendor release note does not state that these vulnerabilities are under active exploitation.
Impact
- Arbitrary code execution inside the Chrome sandbox (CVE-2026-16805 and CVE-2026-16806)
- Potential Chrome sandbox escape (CVE-2026-16804 and CVE-2026-16807)
- Potential compromise of the confidentiality, integrity, and availability of the affected endpoint
Solution / Workarounds
Before deployment, review the vendor advisory and test the update in accordance with the organization's change-management procedures.
Apply the latest Google Chrome Stable security update:
- Update Chrome to version 150.0.7871.186/.187 or later on Windows and macOS.
- Update Chrome to version 150.0.7871.186 or later on Linux.
- Restart Chrome after updating and verify the installed version from Menu > Help > About Google Chrome.
- Enable automatic browser updates.
- Monitor managed endpoints for failed or pending browser updates.
- Prioritize devices used to browse untrusted internet content or access sensitive organizational systems.
Reference
- Google Chrome Stable Channel Update for Desktop – 23 July 2026
- NVD – CVE-2026-16804
- NVD – CVE-2026-16805
- NVD – CVE-2026-16806
- NVD – CVE-2026-16807
- CERT-FR Advisory CERTFR-2026-AVI-0925
Disclaimer
The information provided herein is based on public vendor and government sources available as of 28 July 2026 and is provided on an "as is" basis, without warranty of any kind.