Chrome 148 Update Patches Critical Vulnerabilities
securityweek
Google this week released a Chrome 148 update that resolves 79 vulnerabilities, including 14 critical-severity bugs across multiple components.
The first critical issue is a heap buffer overflow in WebML tracked as CVE-2026-8509, for which the internet giant paid a $43,000 bug bounty.
Google has not shared details on the flaw, but its severity rating and the paid amount suggest that it could be exploited for remote code execution.
The second critical issue is CVE-2026-8510, an integer overflow weakness in Skia that earned the reporting researcher a $25,000 reward.
The remaining 12 critical-severity security defects resolved with the latest Chrome refresh were all discovered by Google.
They include eight use-after-free vulnerabilities in UI, FileSystem, Input, Aura, HID, Blink, Tab Groups, and Downloads, an insufficient validation of untrusted input flaw in DataTransfer, an object lifecycle issue in WebShare, an integer overflow bug in ANGLE, and a race condition in ...
Copyright of this story solely belongs to securityweek . To see the full text click HERE

