Saturday , September 26 2026
382

Chrome Update Patches 382 Vulnerabilities, Including 15 Critical

Chrome 151 has a new update that fixes 382 security problems. This includes 15 critical issues that could allow attackers to run harmful code and take over the browser if not fixed.

Google is sending out this update for Windows, macOS, Linux, and Chrome for iOS. The update has security fixes for many important parts of the browser. Google’s release notes say that Chrome 151 (with desktop build 150.0.7871.46) has 382 different security fixes that are part of the Chrome Vulnerability Rewards Program.
Bug details remain partially restricted until the majority of users receive the update, in line with Google’s standard coordinated disclosure process.

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

The patch set fixes serious flaws like remote code execution and minor issues with the user interface and rules for web, graphics, casting, networking, and iOS parts.

Many of these bugs were found by Google with current memory-safety tools like AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, and fuzzing tools.

Chrome Update Patches 382 Vulnerabilities

CVE ID Component Root cause / bug class Reported by Report date
CVE-2026-13774 Extensions Use after free in Extensions Google 2026-04-26
CVE-2026-13775 GPU Use after free in GPU Google 2026-05-10
CVE-2026-13776 Dawn Type confusion in Dawn Google 2026-05-14
CVE-2026-13777 iOSWeb Insufficient validation of untrusted input in iOSWeb Google 2026-05-14
CVE-2026-13778 WebUSB Use after free in WebUSB Google 2026-05-14
CVE-2026-13779 Chromoting Use after free in Chromoting Google 2026-05-14
CVE-2026-13780 ANGLE Insufficient validation of untrusted input in ANGLE Google 2026-05-19
CVE-2026-13781 Skia Insufficient validation of untrusted input in Skia Google 2026-05-25
CVE-2026-13782 Browser Use after free in Browser Google 2026-05-26
CVE-2026-13783 Views Use after free in Views Google 2026-05-27
CVE-2026-13784 Views Use after free in Views Google 2026-05-27
CVE-2026-13785 Bluetooth Use after free in Bluetooth Google 2026-05-27
CVE-2026-13786 Ozone Use after free in Ozone Google 2026-05-29
CVE-2026-13787 Chromoting Use after free in Chromoting Google 2026-06-11
CVE-2026-13788 Fullscreen Use after free in Fullscreen Google 2026-06-12

Mitigations

Google recommends that all users update to the latest Chrome 151 stable release as soon as possible to mitigate the risk of code execution attacks based on these vulnerabilities.

Check Also

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could …