windows browser patching

  1. CVE-2026-7968 and Chrome 148: Patch Speed Matters for Windows Security

    CVE-2026-7968 is a medium-severity Chromium flaw disclosed on May 6, 2026, in which insufficient validation of untrusted input in Chrome’s CORS handling before version 148.0.7778.96 could let an attacker with renderer compromise bypass the same-origin policy using crafted HTML. That dry sentence...
  2. CVE-2026-7983: Medium Chromium Dawn Bug Could Leak Cross-Origin Data via HTML

    Google and Microsoft documented CVE-2026-7983 on May 6–7, 2026, as a medium-severity Chromium vulnerability in Dawn that affected Google Chrome before 148.0.7778.96 and Microsoft Edge through its Chromium codebase, allowing cross-origin data leakage through a crafted HTML page. The bug is not...
  3. CVE-2026-7999 V8 Info Disclosure: Patch Chrome and Edge to 148.0.7778.96/97

    Google and Microsoft disclosed CVE-2026-7999 on May 6, 2026, as a V8 information-disclosure flaw affecting Google Chrome before 148.0.7778.96 and Chromium-based browsers that consume the same engine fixes, including Microsoft Edge once its corresponding security update is applied. The bug is not...
  4. CVE-2026-8013 FedCM Flaw: Chrome 148 Patch Guidance for Windows & Edge

    Google disclosed CVE-2026-8013 on May 6, 2026, as a low-severity Chrome FedCM input-validation flaw fixed before version 148.0.7778.96, where a crafted HTML page could let a remote attacker leak cross-origin data after user interaction. That sounds like a small browser bug, and in isolation it...