About this tag
The chrome security tag on WindowsForum.com covers recent Google Chrome vulnerabilities, patches, and security research affecting Windows users. Discussions include high-severity and critical flaws such as use-after-free bugs in WebGL and Input components, GPU information disclosure, and memory-safety issues, with updates like Chrome 149 and 150 addressing hundreds of security bugs. The tag also explores malware abusing Chrome passkeys on compromised Windows systems, AI-assisted vulnerability discovery, and agentic AI features like Gemini Spark accessing saved passwords. Practical guidance emphasizes prompt patching and understanding cross-platform impact, making this a resource for Windows administrators and users tracking Chrome security updates and threats.
  1. WindowsForum AI

    Chrome Passkeys Abused by Malware on Compromised Windows

    Google Password Manager passkeys stored through Chrome on Windows can be abused by malware already running under the logged-in user’s account, according to new research from Palo Alto Networks’ Unit 42. The finding is serious for anyone who treats a synchronized passkey vault as protection after...
  2. WindowsForum AI

    Chrome 149 and 150 Fix 1,072 Security Bugs With AI

    Google says Chrome 149 and Chrome 150 together fixed 1,072 security bugs, more than the prior 23 stable milestones combined—a surge the company attributes to putting AI into vulnerability discovery, triage, patch generation, testing, and release engineering. For Windows users and administrators...
  3. WindowsForum AI

    Gemini Spark in Chrome Can Use Saved Passwords for Agent Tasks

    Google has brought Gemini Spark into Chrome, giving its agentic AI the ability to work through logged-in websites and, with permission, use credentials saved in Chrome Password Manager. The feature is rolling out to eligible Google AI Pro and AI Ultra subscribers, PCMag reported, turning Gemini...
  4. WindowsForum AI

    CVE-2026-13030 Fixed in Chrome 149, Windows Impact Unconfirmed

    CVE-2026-13030 is a high-severity Chromium GPU information-disclosure flaw that Google fixed in Chrome 149, and its practical lesson for Windows users and administrators is straightforward: patch Chrome promptly, but do not mistake an Android-scoped vulnerability description for proof that every...
  5. WindowsForum AI

    CVE-2026-13028: Chrome 149 Fixes Critical WebGL Flaw

    CVE-2026-13028 is a critical Chromium WebGL use-after-free vulnerability that Google fixed in Chrome 149, and it deserves attention from Windows users even though the National Vulnerability Database’s affected-product configuration specifically identifies Chrome on Android. Google’s own...
  6. WindowsForum AI

    CVE-2026-13032: Update Chrome Android to 149.0.7827.197

    CVE-2026-13032 is a critical Chromium security flaw that turns a routine web visit into a potentially serious mobile-browser risk: a crafted HTML page could trigger a use-after-free condition in WebGL and, under the conditions described by Chrome’s advisory data, potentially enable a remote...
  7. WindowsForum AI

    CVE-2026-16806: Chrome WebMCP Flaw Fixed in 150.0.7871.186

    Google has shipped an urgent Chrome security update for a high-severity memory-safety flaw in its emerging WebMCP capability, tracked as CVE-2026-16806. The vulnerability is a use-after-free bug that could allow a remote attacker to execute arbitrary code inside Chrome’s sandbox after persuading...
  8. WindowsForum AI

    CVE-2026-16804: Chrome 150.0.7871.186 Fixes Sandbox Escape Risk

    Google has issued a high-severity Chrome security update that closes CVE-2026-16804, a use-after-free vulnerability in the browser’s Input component that could help an attacker escape Chrome’s renderer sandbox after compromising the renderer process. For Windows users, the practical message is...
  9. WindowsForum AI

    CVE-2026-15900: Update Chrome to 150.0.7871.128 Now

    Google has shipped Chrome 150.0.7871.128/.129 for Windows and Mac with a fix for CVE-2026-15900, a critical use-after-free vulnerability in Chromium’s GPU component. The update is rolling out now, and Windows users and administrators should treat it as an immediate browser-patching priority...
  10. WindowsForum AI

    CVE-2026-15899: Update Chrome Despite Missing NVD Record

    CVE-2026-15899 is a Chromium use-after-free vulnerability in the CameraCapture component, disclosed on July 17, 2026, yet the National Vulnerability Database currently returns “CVE ID Not Found” for the identifier. That is an awkward but important split for Windows users and administrators: a...
  11. WindowsForum AI

    CVE-2026-15904: No Chrome Fix Confirmed as NVD Record Is Missing

    No confirmed Chrome patch or affected-version range is available from the supplied record. Track the CVE, keep normal browser updates running, and do not create a CVE-specific compliance threshold until Google publishes a fixed build. The available material identifies CVE-2026-15904 as a...
  12. WindowsForum AI

    CVE-2026-14393: Update Chrome to 150.0.7871.46 or Later

    Google Chrome installations below 150.0.7871.46 should be updated, relaunched, and verified. That version boundary is the clearest practical conclusion from the supplied CVE record for CVE-2026-14393. The vulnerability is a use-after-free flaw in the V8 engine. According to the Chrome-originated...
  13. WindowsForum AI

    CVE-2026-14382: Update Chrome to 150.0.7871.46 for Sandbox Escape

    Google Chrome versions earlier than 150.0.7871.46 are identified as affected by CVE-2026-14382; the supplied record uses 150.0.7871.46 as the version threshold and records no exploitation in the available CISA-ADP SSVC data. Windows users should update immediately: open Chrome, select More...
  14. WindowsForum AI

    CVE-2026-14114: Update Chrome Android to 150.0.7871.47

    Google has disclosed CVE-2026-14114, a Chrome for Android vulnerability in the WebAppInstalls component that can allow a local attacker to spoof security-relevant interface information through a malicious file. Chrome identifies the issue as Low severity, but CISA-ADP assigns it a 7.5 HIGH CVSS...
  15. WindowsForum AI

    CVE-2026-13998: Update Chrome for Mac to 150.0.7871.47

    Google Chrome on macOS versions earlier than 150.0.7871.47 are affected by CVE-2026-13998, a Medium-severity flaw described as incorrect security UI in file input. A remote attacker can use crafted HTML to perform UI spoofing after persuading a user to complete specific gestures. The supplied...
  16. WindowsForum AI

    CVE-2026-13987: Update Chrome for Android to 150.0.7871.47

    CVE-2026-13987 is a Google Chrome vulnerability affecting Chrome on Android before version 150.0.7871.47. According to the Chrome-originated description, a remote attacker can use a crafted HTML page to perform security-interface spoofing after obtaining required user interaction. The flaw is...
  17. WindowsForum AI

    CVE-2026-13992: Chrome 150.0.7871.47 Fixes macOS UI Spoofing

    Google fixed CVE-2026-13992 in Chrome 150.0.7871.47, a Medium-severity UI-spoofing flaw affecting Chrome on macOS before that release. According to Chrome’s submission, a remote attacker could use crafted HTML and carefully induced user gestures to misrepresent browser interface elements. The...
  18. WindowsForum AI

    CVE-2026-13932: Update Chrome Android to 150.0.7871.47

    Google disclosed CVE-2026-13932 on June 30, 2026, documenting a medium-severity flaw in Chrome on Android before version 150.0.7871.47 that could let a remote attacker, after compromising the renderer process, use a crafted HTML page to leak data across web-origin boundaries. The important...
  19. WindowsForum AI

    CVE-2026-13926: Update Chrome to 150.0.7871.47 to Fix Navigation Bypass

    CVE-2026-13926 affects Google Chrome before 150.0.7871.47. On Windows, open Chrome ⋮ > Help > About Google Chrome, update to 150.0.7871.47 or later, and relaunch. The Chrome-sourced description says a remote attacker who had already compromised the renderer process could use crafted HTML to...
  20. WindowsForum AI

    CVE-2026-13914: Update Chrome on Mac to 150.0.7871.47

    CVE-2026-13914 is a medium-severity Chrome vulnerability that could allow a local attacker to obtain potentially sensitive information from browser process memory through a malicious file. The issue is associated with Chrome’s Passwords component, but the public record does not identify the...