HomeCyber BalkansGoogle Chrome 153 Update Addresses 16 Security Flaws, Including Two Critical Vulnerabilities

Google Chrome 153 Update Addresses 16 Security Flaws, Including Two Critical Vulnerabilities

Published on

spot_img

Google Chrome Version 153 Released: Addressing Critical Security Vulnerabilities

In a significant move for user security, Google has announced the release of Chrome version 153 to the Stable desktop channel. This update comes in response to the identification of 16 security vulnerabilities that could impact users and organizations utilizing the browser. Among the vulnerabilities, two have been classified as critical-severity flaws specifically affecting the Dawn graphics component and WebGL, which are integral for rendering web content and applications.

Update Rollout Details

The update, designated as version 153.0.8010.52, is being rolled out for both Windows and macOS platforms. Meanwhile, Linux users will see the same version released in the coming days and weeks. The rapid rollout emphasizes the urgency of addressing potential security risks in real-time, ensuring that users are shielded from exploitation.

Critical Vulnerabilities Explored

Among the security flaws corrected in this update, the most pressing is tracked under CVE-2026-93374, a use-after-free vulnerability present in Dawn—a part of Chromium’s implementation of the WebGPU API. This type of flaw occurs when software continues to access memory that has already been deallocated. The repercussion could manifest as browser crashes, memory corruption, or even unauthorized code execution, depending on specific conditions. Florian Schweitzer disclosed this vulnerability to Google on April 8, 2026, highlighting the importance of community involvement in maintaining software security.

The second critical vulnerability, identified as CVE-2026-93372, is associated with a buffer overflow in WebGL. Such vulnerabilities could allow malicious actors to write data outside of allocated memory boundaries, leading to browser crashes or more severe exploitation cases. Google was informed of this WebGL issue on August 17, 2026, underscoring the growing need for robust security measures within web graphics.

Both of these vulnerabilities can adversely affect graphics-related browser components that deal with potentially untrusted content originating from diverse websites and web applications. Although Google has opted not to disclose specific technical exploit details for these vulnerabilities, the critical severity rating indicates a pressing need for organizations and individual Chrome users alike to implement the patch without delay.

Additional Security Fixes

Beyond the critical vulnerabilities, Chrome 153 also mitigates seven high-severity vulnerabilities across various Chromium subsystems. This array of fixes includes a use-after-free flaw in PDFium, the PDF rendering component of Chromium, along with another buffer overflow issue in PDFium itself. Document-rendering capabilities are often targeted by attackers, as malicious PDF files can be disseminated through phishing emails and compromised websites.

Other high-severity issues addressed in this update cover a range of problems, such as incorrect reference resolution in Tracing, improper state validation in Skia, and use-after-free vulnerabilities in the Extensions component. A critical type confusion flaw that affects the V8 JavaScript and WebAssembly engine is particularly significant, as such weaknesses threaten memory safety when processing content controlled by attackers.

Apart from the high-severity vulnerabilities, Chrome 153 rectifies six medium-severity issues, including a race condition in FileSystem and server-side request forgery in Omnibox, among others. The list of fixes extends to address various informational leaks and authorization mishaps that could compromise user data security.

One minor yet notable fix is CVE-2026-93386, a low-severity UI misrepresentation issue in WebAppInstalls. Such problems can distort users’ interpretations of installation prompts or browser interface elements, which could heighten the risk of social engineering attacks.

Call to Action for Administrators and Users

In light of these vulnerabilities, administrators are strongly encouraged to prioritize the deployment of Chrome 153 across managed environments, be they Windows, macOS, or Linux. This initiative is imperative, particularly due to the memory-safety flaws prevalent in browser-exposed graphics, PDF functionalities, extensions, and JavaScript components.

Users can easily verify their installed version of Chrome by navigating to the Chrome menu, selecting Help, and then choosing "About Google Chrome." Although Chrome should automatically update to the latest version, a browser restart will be necessary to activate the patched version completely.

Conclusion

Google has reiterated that further details regarding these vulnerabilities may remain confidential until a significant portion of users has applied the update. This practice is crucial for minimizing the risk of vulnerabilities being weaponized before the majority of users are secured against potential exploitation. By fortifying this widely used browser, Google demonstrates its commitment to ensuring web security and user safety in an ever-evolving digital landscape.

Source link

Latest articles

Anthropic Tests Claude Money for Bank Data Analysis

Anthropic Expands AI Capabilities with Launch of Claude Money: A Look at Its Financial...

JADEPUFFER Enhances Agentic Ransomware to Focus on AI Models and Training Data

Evolution of the JADEPUFFER Threat: Targeting AI and Machine Learning Assets The cybersecurity landscape is...

SE Labs Introduces PIVOT Testing Program for Cybersecurity Vendors

SE Labs Launches New Cybersecurity Testing Program: PIVOT On September 15, SE Labs, a prominent...

PowerShell Malware Exploits Registry and DNS TXT Records for XMRig Crypto Miner Deployment

A sophisticated cryptomining campaign has recently come to light, employing intricate layers of obfuscation...

More like this

Anthropic Tests Claude Money for Bank Data Analysis

Anthropic Expands AI Capabilities with Launch of Claude Money: A Look at Its Financial...

JADEPUFFER Enhances Agentic Ransomware to Focus on AI Models and Training Data

Evolution of the JADEPUFFER Threat: Targeting AI and Machine Learning Assets The cybersecurity landscape is...

SE Labs Introduces PIVOT Testing Program for Cybersecurity Vendors

SE Labs Launches New Cybersecurity Testing Program: PIVOT On September 15, SE Labs, a prominent...