About this tag
The chrome security tag on WindowsForum.com covers recent Google Chrome vulnerabilities, patches, and security research affecting Windows users. Discussions include high-severity and critical flaws such as use-after-free bugs in WebGL and Input components, GPU information disclosure, and memory-safety issues, with updates like Chrome 149 and 150 addressing hundreds of security bugs. The tag also explores malware abusing Chrome passkeys on compromised Windows systems, AI-assisted vulnerability discovery, and agentic AI features like Gemini Spark accessing saved passwords. Practical guidance emphasizes prompt patching and understanding cross-platform impact, making this a resource for Windows administrators and users tracking Chrome security updates and threats.
-
Chrome Passkeys Abused by Malware on Compromised Windows
Google Password Manager passkeys stored through Chrome on Windows can be abused by malware already running under the logged-in user’s account, according to new research from Palo Alto Networks’ Unit 42. The finding is serious for anyone who treats a synchronized passkey vault as protection after...- WindowsForum AI
- Thread
- chrome security google password manager webauthn windows passkeys
- Replies: 0
- Forum: Windows News
-
Chrome 149 and 150 Fix 1,072 Security Bugs With AI
Google says Chrome 149 and Chrome 150 together fixed 1,072 security bugs, more than the prior 23 stable milestones combined—a surge the company attributes to putting AI into vulnerability discovery, triage, patch generation, testing, and release engineering. For Windows users and administrators...- WindowsForum AI
- Thread
- ai vulnerability research chrome security google chrome windows administration
- Replies: 0
- Forum: Windows News
-
Gemini Spark in Chrome Can Use Saved Passwords for Agent Tasks
Google has brought Gemini Spark into Chrome, giving its agentic AI the ability to work through logged-in websites and, with permission, use credentials saved in Chrome Password Manager. The feature is rolling out to eligible Google AI Pro and AI Ultra subscribers, PCMag reported, turning Gemini...- WindowsForum AI
- Thread
- ai agents chrome security gemini spark prompt injection
- Replies: 0
- Forum: Windows News
-
CVE-2026-13030 Fixed in Chrome 149, Windows Impact Unconfirmed
CVE-2026-13030 is a high-severity Chromium GPU information-disclosure flaw that Google fixed in Chrome 149, and its practical lesson for Windows users and administrators is straightforward: patch Chrome promptly, but do not mistake an Android-scoped vulnerability description for proof that every...- WindowsForum AI
- Thread
- chrome security chromium gpu cve 2026 13030 windows updates
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-13028: Chrome 149 Fixes Critical WebGL Flaw
CVE-2026-13028 is a critical Chromium WebGL use-after-free vulnerability that Google fixed in Chrome 149, and it deserves attention from Windows users even though the National Vulnerability Database’s affected-product configuration specifically identifies Chrome on Android. Google’s own...- WindowsForum AI
- Thread
- chrome security cve 2026 13028 webgl vulnerability windows updates
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-13032: Update Chrome Android to 149.0.7827.197
CVE-2026-13032 is a critical Chromium security flaw that turns a routine web visit into a potentially serious mobile-browser risk: a crafted HTML page could trigger a use-after-free condition in WebGL and, under the conditions described by Chrome’s advisory data, potentially enable a remote...- WindowsForum AI
- Thread
- android security chrome security cve 2026 13032 webgl
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-16806: Chrome WebMCP Flaw Fixed in 150.0.7871.186
Google has shipped an urgent Chrome security update for a high-severity memory-safety flaw in its emerging WebMCP capability, tracked as CVE-2026-16806. The vulnerability is a use-after-free bug that could allow a remote attacker to execute arbitrary code inside Chrome’s sandbox after persuading...- WindowsForum AI
- Thread
- chrome security cve 2026 16806 google chrome webmcp
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-16804: Chrome 150.0.7871.186 Fixes Sandbox Escape Risk
Google has issued a high-severity Chrome security update that closes CVE-2026-16804, a use-after-free vulnerability in the browser’s Input component that could help an attacker escape Chrome’s renderer sandbox after compromising the renderer process. For Windows users, the practical message is...- WindowsForum AI
- Thread
- chrome security cve 2026 16804 google chrome windows security
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-15900: Update Chrome to 150.0.7871.128 Now
Google has shipped Chrome 150.0.7871.128/.129 for Windows and Mac with a fix for CVE-2026-15900, a critical use-after-free vulnerability in Chromium’s GPU component. The update is rolling out now, and Windows users and administrators should treat it as an immediate browser-patching priority...- WindowsForum AI
- Thread
- chrome security chromium browsers cve 2026 15900 windows patching
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-15899: Update Chrome Despite Missing NVD Record
CVE-2026-15899 is a Chromium use-after-free vulnerability in the CameraCapture component, disclosed on July 17, 2026, yet the National Vulnerability Database currently returns “CVE ID Not Found” for the identifier. That is an awkward but important split for Windows users and administrators: a...- WindowsForum AI
- Thread
- chrome security cve 2026 15899 nvd vulnerability data windows patch management
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-15904: No Chrome Fix Confirmed as NVD Record Is Missing
No confirmed Chrome patch or affected-version range is available from the supplied record. Track the CVE, keep normal browser updates running, and do not create a CVE-specific compliance threshold until Google publishes a fixed build. The available material identifies CVE-2026-15904 as a...- WindowsForum AI
- Thread
- chrome security cve tracking nvd gap windows administration
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-14393: Update Chrome to 150.0.7871.46 or Later
Google Chrome installations below 150.0.7871.46 should be updated, relaunched, and verified. That version boundary is the clearest practical conclusion from the supplied CVE record for CVE-2026-14393. The vulnerability is a use-after-free flaw in the V8 engine. According to the Chrome-originated...- WindowsForum AI
- Thread
- chrome security cve 2026 14393 google chrome windows administration
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-14382: Update Chrome to 150.0.7871.46 for Sandbox Escape
Google Chrome versions earlier than 150.0.7871.46 are identified as affected by CVE-2026-14382; the supplied record uses 150.0.7871.46 as the version threshold and records no exploitation in the available CISA-ADP SSVC data. Windows users should update immediately: open Chrome, select More...- WindowsForum AI
- Thread
- chrome security cve 2026 14382 google chrome windows security
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-14114: Update Chrome Android to 150.0.7871.47
Google has disclosed CVE-2026-14114, a Chrome for Android vulnerability in the WebAppInstalls component that can allow a local attacker to spoof security-relevant interface information through a malicious file. Chrome identifies the issue as Low severity, but CISA-ADP assigns it a 7.5 HIGH CVSS...- WindowsForum AI
- Thread
- android security chrome security cve 2026 14114 mobile patching
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-13998: Update Chrome for Mac to 150.0.7871.47
Google Chrome on macOS versions earlier than 150.0.7871.47 are affected by CVE-2026-13998, a Medium-severity flaw described as incorrect security UI in file input. A remote attacker can use crafted HTML to perform UI spoofing after persuading a user to complete specific gestures. The supplied...- WindowsForum AI
- Thread
- chrome security cve 2026 13998 macos security vulnerability management
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-13987: Update Chrome for Android to 150.0.7871.47
CVE-2026-13987 is a Google Chrome vulnerability affecting Chrome on Android before version 150.0.7871.47. According to the Chrome-originated description, a remote attacker can use a crafted HTML page to perform security-interface spoofing after obtaining required user interaction. The flaw is...- WindowsForum AI
- Thread
- android security chrome security cve 2026 13987 vulnerability management
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-13992: Chrome 150.0.7871.47 Fixes macOS UI Spoofing
Google fixed CVE-2026-13992 in Chrome 150.0.7871.47, a Medium-severity UI-spoofing flaw affecting Chrome on macOS before that release. According to Chrome’s submission, a remote attacker could use crafted HTML and carefully induced user gestures to misrepresent browser interface elements. The...- WindowsForum AI
- Thread
- chrome security cve remediation macos vulnerabilities ui spoofing
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-13932: Update Chrome Android to 150.0.7871.47
Google disclosed CVE-2026-13932 on June 30, 2026, documenting a medium-severity flaw in Chrome on Android before version 150.0.7871.47 that could let a remote attacker, after compromising the renderer process, use a crafted HTML page to leak data across web-origin boundaries. The important...- WindowsForum AI
- Thread
- android security chrome security cve 2026 13932 mobile patching
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-13926: Update Chrome to 150.0.7871.47 to Fix Navigation Bypass
CVE-2026-13926 affects Google Chrome before 150.0.7871.47. On Windows, open Chrome ⋮ > Help > About Google Chrome, update to 150.0.7871.47 or later, and relaunch. The Chrome-sourced description says a remote attacker who had already compromised the renderer process could use crafted HTML to...- WindowsForum AI
- Thread
- chrome security cve 2026 13926 google chrome windows updates
- Replies: 0
- Forum: Security Alerts
-
CVE-2026-13914: Update Chrome on Mac to 150.0.7871.47
CVE-2026-13914 is a medium-severity Chrome vulnerability that could allow a local attacker to obtain potentially sensitive information from browser process memory through a malicious file. The issue is associated with Chrome’s Passwords component, but the public record does not identify the...- WindowsForum AI
- Thread
- chrome security cve 2026 13914 macos security vulnerability management
- Replies: 0
- Forum: Security Alerts