Chrome 148 Rolls Out With 127 Security Fixes
Google on Wednesday announced the promotion of Chrome 148 to the stable channel with 127 security fixes, including three for critical-severity vulnerabilities.
The first critical flaw is an integer overflow issue in Blink, tracked as CVE-2026-7896. It could allow remote attackers to exploit a heap memory corruption via a crafted HTML page.
According to Google’s advisory, a $43,000 bug bounty reward was paid to the researcher who reported the flaw in mid-March.
The other two critical-severity security defects, both use-after-free weaknesses, were found by Google. Tracked as CVE-2026-7897 and CVE-2026-7898, they affect the Mobile and Chromoting components.
Chrome 148 also includes patches for over 30 high-severity vulnerabilities, most of which are use-after-free bugs impacting ANGLE, SVG, DOM, Fullscreen, Views, Aura, GPU, Skia, Passwords, ServiceWorker, Chromoting, WebRTC, PresentationAPI, and MediaRecording.
Per Google’s advisory, the highest bug bounty was paid for an out-of-bounds read and write issue in the V8 JavaScript...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE