Google Chrome’s Security Update Decision—New Browser Danger Confirmed

Google Chrome’s Security Update Decision—New Browser Danger Confirmed

Google confirms system takeover threat Chrome update.

Anadolu Agency via Getty Images

Google has released Chrome 145.0.7632.116/117, a security update for all Windows, Mac and Linux users. Don’t delay, update your browser now, as the vulnerabilities addressed include threats of system takeover and cryptographic key access.

Although none of the three confirmed security vulnerabilities, CVE-2026-3061, CVE-2026-3062, and CVE-2026-3063, are known to have been exploited by attackers at this point in time, that threat window can only be firmly closed by ensuring your browser is updated, and that update is activated.

ForbesPayPal Data Breach Confirmed—Money Was Stolen, Passwords Now ResetBy Davey Winder

As is the norm, the latest Google Chrome security update alert does not provide a whole lot of detail about the vulnerabilities that it has fixed. In fact, beyond the Common Vulnerabilities and Exposures designation, a broad technical categorization of the vulnerability type and, where appropriate, the name of the researcher responsible for disclosing it, Google is staying very tight-lipped indeed. This makes sense, as Google itself stated: “Access to bug details and links may be kept restricted until a majority of users are updated with a fix.” No point giving threat actors too much of a technical heads up, after all. That said, it is possible to provide an overview of each vulnerability without handing over the exploit treasure chest keys to hackers. So, here goes.

Google Chrome Security Vulnerability CVE-2026-3061

CVE-2026-3061 is an out-of-bounds read vulnerability in the Media component of Google Chrome. Simply put, this means that the component reads memory either past or before the intended buffer zones, potentially allowing an attacker to “get secret values such as cryptographic keys, PII, memory addresses, or other information that could be used in additional attacks,” as the applicable Common Weakness Enumeration 125 description describes it. As far as I can tell, no user interaction or authentication would be required to exploit this vulnerability, beyond the initial act of visiting a site that hosts a maliciously crafted HTML page.

Google Chrome Security Vulnerability CVE-2026-3062

CVE-2026-3062 is another out-of-bounds vulnerability, this time impacting macOS users and Chrome’s Tint component. Once again, this requires just the use of a maliciously-crafted web page, and could potentially enable an attacker to execute unauthorized code and steal sensitive data. Because it is capable of remote execution, and again requires no previous authentication, like both CVE-2026-3061 and CVE-2026-3063, this is a high-severity-rated CVE.

Google Chrome Security Vulnerability CVE-2026-3063

And finally, CVE-2026-3063 is what’s known as an inappropriate implementation, letting something do something that it shouldn’t, in other words, within the Google Chrome DevTools implementation. In this case, as I understand it, it could involve injecting malicious scripts into privileged pages. This would require the installation of a dodgy extension by the user. The potential fallout from this could be unauthorized code execution and all that comes with it.

ForbesNew AI Data Leaks—More Than 1 Billion IDs And Photos ExposedBy Davey Winder

The Latest Google Chrome Security Update Decision

The good news is that Google has already started rolling out the necessary security updates for all Chrome browser users, and these will be installed automatically. The bad news is that this process is not instantaneous: Google has stated that the updates “will roll out over the coming days/weeks.” I would advise, as I have before and will do again, to preempt the patches arriving with you and kickstart the update process yourself. This simplicity itself. Either turn your browser off and on again to see if an update installs, or head to the Help|About Google Chrome option in the three-dot menu.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *