Google Chrome Issues Two Security Updates, Fixing 21 Flaws
The second update arrived just two days after the first, indicating a rapid response to newly discovered vulnerabilities.
Reporting from 1 sources: ASCII.jp.
Google released two security updates for Chrome in the same week, patching a total of 21 vulnerabilities. The first update, on June 23, fixed 18 flaws, including four rated Critical and 14 rated High. The Critical vulnerabilities included a use-after-free in WebGL (CVE-2026-13028), an out-of-bounds read in Blink's InterestGroups (CVE-2026-13033), and a use-after-free in Autofill (CVE-2026-13038). The second update, on June 25, addressed three High-severity issues: an integer overflow in Mojo (CVE-2026-13281), a use-after-free in Payments (CVE-2026-13282), and a use-after-free in AdFilter (CVE-2026-13283). The desktop versions for Windows and macOS were updated to 149.0.7827.196/197 after the first patch and to 149.0.7827.200/201 after the second. Linux received 149.0.7827.196 and then 149.0.7827.200. Android users got 149.0.7827.197 and later 149.0.7827.200. Google is rolling out the desktop updates gradually over the next few days to weeks, with manual updates available from Chrome's settings. The Android versions are expected on Google Play within a few days.
The June 23 update fixed 18 vulnerabilities, with four rated Critical and 14 High. The Critical CVEs included CVE-2026-13028 (use-after-free in WebGL), CVE-2026-13033 (out-of-bounds read in Blink>InterestGroups), and CVE-2026-13038 (use-after-free in Autofill). The High-severity flaws included CVE-2026-13021 (inappropriate implementation in DeviceBoundSessionCredentials), CVE-2026-13022 (inappropriate implementation in Autofill), and CVE-2026-13025 (insufficient validation of untrusted input in DevTools). The June 25 follow-up patched three High-severity issues: CVE-2026-13281 (integer overflow in Mojo), CVE-2026-13282 (use-after-free in Payments), and CVE-2026-13283 (use-after-free in AdFilter). Desktop users on Windows and macOS received version 149.0.7827.196/197 after the first patch and 149.0.7827.200/201 after the second. Linux users got 149.0.7827.196 and then 149.0.7827.200. Android users received 149.0.7827.197 and later 149.0.7827.200. Google is rolling out the desktop updates gradually over the next few days to weeks, with manual updates available from Chrome's settings. The Android versions are expected on Google Play within a few days.
Synthesized by Yomimono from the 1 cited source below, including Japanese-language reporting where cited, then editorially reviewed before publishing.
Sources
- ASCII.jp グーグルChromeに深刻度”高”の脆弱性 今週2度目のアップデート