Google Patches 42 Chrome Security Flaws Including Three Critical Bugs

news
Google Patches 42 Chrome Security Flaws Including Three Critical Bugs

Google has released a major Chrome security update that fixes 42 vulnerabilities across the browser, including three flaws rated critical.

The update is available through Chrome 153.0.8010.47 and 153.0.8010.48 for Windows and macOS, while Linux users are receiving version 153.0.8010.47. Google says none of the vulnerabilities included in this release are known to have been exploited in active attacks so far.

That is still a strong reason to update quickly. Several of the vulnerabilities affect memory handling, including multiple use after free flaws that could potentially allow an attacker to trigger unexpected behavior after memory has already been released.

Three critical bugs lead a large security update

Among the 42 vulnerabilities fixed, three are rated critical. Two of those involve use after free problems in Chrome's Internals and Workers components.

Google also classified another 28 vulnerabilities as high severity. Most of the remaining issues are medium severity, with one rated low.

Use after free bugs are particularly prominent in this release, appearing 12 times across the vulnerability list. These flaws happen when software continues to access an area of memory after it has already been released, which can create opportunities for crashes or more serious security problems.

Security detailChrome September 2026 update
Total vulnerabilities fixed42
Critical severity3
High severity28
Most common bug typeUse after free
Use after free flaws12
Found internally by Google26
Reported by external researchers16
Known active exploitationNone reported
Windows and macOS version153.0.8010.47 or .48
Linux version153.0.8010.47

Google discovered 26 of the vulnerabilities internally, while outside security researchers reported another 16.

The company has so far paid $2,500 in bug bounties connected with the externally reported issues. Additional reward amounts may still be determined later depending on Google's normal vulnerability review process.

Chrome should update automatically

Chrome normally installs security updates automatically, although the browser may require a restart before the latest version becomes active.

You can manually check your installation by opening Chrome's menu and going to Help, then About Google Chrome. The browser should automatically search for the newest available version and install it if necessary.

Restarting Chrome after installation completes ensures that the patched build is actually running.

The update is especially relevant because Chrome is widely used across Windows, macOS, Linux, Android, and iOS. Keeping the browser current reduces exposure to vulnerabilities that may become more attractive to attackers after technical details are disclosed.

Android receives the same security fixes

Google has also released Chrome 153.0.8010.47 for Android. That build includes the same security fixes as the desktop versions.

On iOS, Chrome 154.0.8037.41 has also been released this week. Chrome on Apple's platform relies on different underlying browser technology, but Google continues to update the application separately.

The Extended Stable Channel for Windows and macOS has meanwhile moved to Chromium 152.0.7977.130.

Chrome 154 is expected to arrive as early as next week, but there is little reason to wait for the next major version before applying the current security patches.

No active exploitation has been reported for these 42 vulnerabilities, which means the update is preventative rather than a response to a confirmed attack campaign. That situation can change, however, once patched vulnerabilities become publicly understood.

For that reason, installing Chrome 153.0.8010.47 or newer is the simplest way to make sure the newly disclosed security problems are addressed on your system.

Discover: News

Discussion (0)

Be the first to comment.