{"id":2137,"date":"2026-07-31T15:09:14","date_gmt":"2026-07-31T15:09:14","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2137"},"modified":"2026-07-31T15:09:14","modified_gmt":"2026-07-31T15:09:14","slug":"three-recent-chrome-releases-fix-1442-flaws-more-than-prior-23-updates-combined","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2137","title":{"rendered":"Three Recent Chrome Releases Fix 1,442 Flaws, More Than Prior 23 Updates Combined"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Jul 31, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Browser Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiqUoKsOzzL1DJubfk79p5F7EfcWUNP-tPwTMNDt329zqRohKeX2tE3qxMCciII-FZEHofHM72OihyAfF_7Eqs48MRmxxVOcGZyKML5LHynh5Akf1fWeNSsDlY2D-EaGLx2T9wy6y2jNfOGx-5xmKNhf0koUmkpIGcuShRA47RVW_207PVhnxdlPijMUmkx\/s1700-e365\/chrome.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Google on Thursday <a href=\"https:\/\/blog.google\/security\/chrome-stronger-with-every-update\/\" target=\"_blank\">announced<\/a> that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of flaws the company fixed across the prior 23 milestones combined.<\/p>\n<p>Both versions were released last month. In its latest patch for Chrome 151, released Wednesday, the tech giant resolved 370 flaws, out of which 349 were reported by Google itself. Seven of the vulnerabilities have been marked critical in severity.<\/p>\n<p>The development comes amid an exponential surge in vulnerability discovery, mainly fueled by the advent of large language models (LLMs) that have accelerated the process, leading to an unprecedented spike in new bug reports, so much so that issues are being <a href=\"https:\/\/www.propublica.org\/article\/anthropic-mythos-microsoft-software-vulnerabilities\" target=\"_blank\">flagged at a faster rate<\/a> than companies can fix them.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-vuln-protection-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjQl2axNwsfhbXOFynrg_uAZsvHi3OvNGSA8KJO-BKR8Xm3x7yjKV3EvfY4v5mwXx6LF0uWFb9h9d9iAV_Pi-YYhqimX9wx4OaLdDJEdR215Xrxq_PAtXkaLfQso4pTSjbj6fvh_ZTliLpzWZSZfcoZgyXtKwhN-SSDDlmbtUqGLshc0KqYQGWYHMN52Sl1\/s728-e100\/zz-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>According to <a href=\"https:\/\/nvd.nist.gov\/vuln\/search#\/nvd\/home?resultType=statistics\" target=\"_blank\">statistics<\/a> shared by the U.S. National Vulnerabilities Database (NVD), 46,872 flaws have been recorded so far in 2026, nearing the 49,920 vulnerabilities reported for the entirety of 2025.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>One such vulnerability discovered in the Chrome codebase is a <a href=\"https:\/\/issues.chromium.org\/issues\/487383169\" target=\"_blank\">critical sandbox escape<\/a> in the Navigation component (<a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-3545\" target=\"_blank\">CVE-2026-3545<\/a>, CVSS score: 9.6) that could be exploited to trick the browser into reading local files from the user&#8217;s system. It was <a href=\"https:\/\/chromereleases.googleblog.com\/2026\/03\/stable-channel-update-for-desktop.html\" target=\"_blank\">patched<\/a> by Google earlier this March.<\/p>\n<p>The shortcoming, per Google, was discovered via an agent harness leveraging its Gemini models and remained undetected in its source code for more than 13 years.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhKZkKrgLwdlwgLsWR6ehru-X1-zm4IStPeYG9JU5r25MV1K8fadUUGWtLj85tmeG1hyphenhyphen8pdSlowXdxLxNqfxSBk9h3QgxKcDUZ3nj3vabbrXvB0hQVWCc6_fIXF8IpJBHeH5PnEJccI0DC-RXBv6wad57cvp7qknybnZ7xZw7oY-Q9eDcj3s6YsdBMWcycN\/s1700-e365\/bugs.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhKZkKrgLwdlwgLsWR6ehru-X1-zm4IStPeYG9JU5r25MV1K8fadUUGWtLj85tmeG1hyphenhyphen8pdSlowXdxLxNqfxSBk9h3QgxKcDUZ3nj3vabbrXvB0hQVWCc6_fIXF8IpJBHeH5PnEJccI0DC-RXBv6wad57cvp7qknybnZ7xZw7oY-Q9eDcj3s6YsdBMWcycN\/s1700-e365\/bugs.png\" alt=\"\" border=\"0\" data-original-height=\"675\" data-original-width=\"1200\"\/><\/a><\/div>\n<p>The tech giant, which is in the process of transitioning to a two-week release cadence for major Chrome milestones, alongside weekly security updates, said it&#8217;s piloting a shift to two security releases per week in the face of \u00abfast-moving, AI-powered attacks.\u00bb<\/p>\n<p>\u00abEven with this pace, proper public disclosure remains paramount,\u00bb Google said in a post. \u00abEvery security bug that reaches Chrome Stable, regardless of whether it was discovered internally or reported externally, is documented and disclosed publicly as a standard best practice.\u00bb<\/p>\n<p>Google said it&#8217;s working on automating efforts to generate release notes and CVE descriptions from security bug fixes to mitigate manual bottlenecks and further shorten the window between vulnerability discovery and public disclosure.<\/p>\n<p>Separately, the internet behemoth noted it&#8217;s exploring ways to dynamically apply the patches without the need for restarting Chrome and ensure a seamless session restore in situations where a restart is required for the changes to take effect, thus eliminating delays and shifting the burden away from the end users.<\/p>\n<p>\u00abBy leveraging Chrome&#8217;s multi-process architecture, dynamic patching sequentially replaces background child processes (like the Renderer and GPU) with updated binaries on the fly,\u00bb Google said.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thn.news\/sygnia-webinar\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjnP2BIJTKZ31v-Y_pyvFqC1s6LD-Bo8UNy3UHgqojpVezgaGWw5-sPe5uRK0dfSm3gmDvoKCdHoJnGx1BiTP6Y0qit7D7TCZU_LckTDpdu9eeyuelmJKndEkOxZP6oNPwzguLBCTkAnNkIEvSYaWamKLqYLrJPjnea1V_lz7UcfQkavBo2g3OEGoLyz7mD\/s728-e100\/sygnia-d-4.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abFor example, in Chrome 150, we rolled out a change to take advantage of the unique application state on macOS where applications typically continue running in the background even after all windows are closed. Now, if Chrome detects a pending update while in this windowless state, it automatically restarts.\u00bb<\/p>\n<p>Additionally, Google is taking steps to eliminate entire classes of security issues from Chrome, such as use-after-frees, out-of-bounds weaknesses, and memory safety flaws, by hardening the runtime environment to combat legacy C++ flaws, transitioning to memory-safe languages like Rust, and implementing the browser&#8217;s top-level user interface using HTML, CSS, and TypeScript to further reduce dependencies on traditional C++ frameworks.<\/p>\n<p>That&#8217;s not all. In an attempt to improve browser security, the company said it&#8217;s moving all Chrome third-party dependencies onto automated update pipelines to ensure they are up-to-date.<\/p>\n<p>\u00abEvery bug found and fixed is one less foothold for an attacker,\u00bb Google&#8217;s Chrome Security Team said. \u00abBut discovering and fixing a bug is only half the battle &#8211; we must also ship the fix and apply the update for users faster than adversaries can exploit the bug, and invest in projects that mitigate or eliminate classes of bugs through accelerated release cadences, dynamic patching, and opportune restarts, we are driving toward a browser that is continuously protected without disrupting the user.\u00bb<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Jul 31, 2026Vulnerability \/ Browser Security Google on Thursday announced that it fixed a whopping 1,072 security bugs in Chrome versions 149 and 150, surpassing the total number of&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2138,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[182,2829,1377,11,2828,1739,619],"class_list":["post-2137","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-chrome","tag-combined","tag-fix","tag-flaws","tag-prior","tag-releases","tag-updates"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2137","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2137"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2137\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2138"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2137"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2137"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2137"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}