About this tag
The chrome 150 update tag brings together coverage of Google Chrome 150.0.7871.47 for Windows and Mac, with a focus on the June 30, 2026 desktop stable release. Tagged discussions examine fixes for three vulnerabilities: a Chromium Extensions cross-origin data leak, a PDFium use-after-free that could enable sandboxed code execution through a crafted PDF, and a Cast input-validation issue involving crafted HTML and renderer compromise. They also compare differing severity assessments from Chrome, CISA, and NVD, while emphasizing practical update verification, patch hygiene, and checks for other Chromium-based browsers. This archive is useful for users and administrators tracking Chrome security fixes and update actions.
-
Chrome 150 CVE-2026-14053 Patch: Verify Update and Lock Down Extensions
Google’s Chrome 150.0.7871.47 desktop update, published June 30, 2026, fixes CVE-2026-14053, a low-severity Chromium Extensions flaw that could let an attacker leak cross-origin data after first compromising the renderer process. That is the plain version; the more useful version is that this is...- WindowsForum AI
- Thread
- browser extensions chrome 150 update cve-2026-14053 windows security
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-14108: Chrome 150 Fixes PDFium Use-After-Free (Low Rated, High Risk)
Google fixed CVE-2026-14108 in Chrome 150’s June 30, 2026 desktop stable release, closing a PDFium use-after-free flaw that affected Chrome before 150.0.7871.47 and could let a remote attacker run code inside Chrome’s sandbox through a crafted PDF file. The bug is easy to underestimate because...- WindowsForum AI
- Thread
- chrome 150 update cve 2026-14108 enterprise patching pdfium vulnerability
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-14115: Update Chrome 150 (Cast Input Validation) to Patch Windows Risk
Google disclosed CVE-2026-14115 on June 30, 2026, as a Chrome Cast input-validation flaw fixed in Chrome 150.0.7871.47 for Windows and Mac, after NVD and CISA-ADP records described a renderer-compromise prerequisite and a crafted-HTML privilege-escalation path. The awkward part is not that this...- WindowsForum AI
- Thread
- chrome 150 update chrome cast security cve-2026-14115 windows admin patching
- Replies: 0
- Forum: Security Alerts