Chrome 148 Rolls Out With 127 Security Fixes

https://www.securityweek.com/wp-content/uploads/2023/04/Chrome-Zero-Day-exploits.jpg

Google on Wednesday announced the promotion of Chrome 148 to the stable channel with 127 security fixes, including three for critical-severity vulnerabilities.

The first critical flaw is an integer overflow issue in Blink, tracked as CVE-2026-7896. It could allow remote attackers to exploit a heap memory corruption via a crafted HTML page.

According to Google’s advisory, a $43,000 bug bounty reward was paid to the researcher who reported the flaw in mid-March.

The other two critical-severity security defects, both use-after-free weaknesses, were found by Google. Tracked as CVE-2026-7897 and CVE-2026-7898, they affect the Mobile and Chromoting components.

Chrome 148 also includes patches for over 30 high-severity vulnerabilities, most of which are use-after-free bugs impacting ANGLE, SVG, DOM, Fullscreen, Views, Aura, GPU, Skia, Passwords, ServiceWorker, Chromoting, WebRTC, PresentationAPI, and MediaRecording.

Per Google’s advisory, the highest bug bounty was paid for an out-of-bounds read and write issue in the V8 JavaScript...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE