Google has released Chrome 152 for Windows, macOS, and Linux, delivering 327 security fixes and improvements. The update addresses 10 critical vulnerabilities, making it an important security release for individual users and enterprise environments.
Chrome 152 is rolling out as version 152.0.7977.64 for Linux and version 152.0.7977.64/.65 for Windows and macOS. Google said availability will expand to users over the coming days and weeks.
The most serious flaws are memory-safety issues, including several use-after-free vulnerabilities. Such bugs occur when software continues accessing memory after it has been released.
Attackers may be able to exploit these conditions to crash the browser, access sensitive information, or potentially run code in the context of the affected Chrome process.
Chrome 152 Released With 327 Security Fixes
The critical issues affect several Chrome components. CVE-2026-79282 is a use-after-free vulnerability in ANGLE, the graphics translation layer used by Chrome. The flaw was reported by security researcher Goodluck and earned a $25,000 reward.
Other critical vulnerabilities affect Aura, Chrome’s user-interface framework, Chromecast, Views, Safe Browsing, and Mobile components.
Google assigned CVE-2026-79290 and CVE-2026-79052 to use-after-free flaws in Aura. It also fixed CVE-2026-79054 and CVE-2026-79224, both of which are use-after-free issues in Chromecast.
Chrome 152 further patches CVE-2026-79121, an improper input validation vulnerability in Chromecast; CVE-2026-79150, a use-after-free flaw in Views; CVE-2026-78935, an uninitialized-variable issue in Mobile; and CVE-2026-79012, a use-after-free bug in Safe Browsing.
Fixes 10 Critical Vulnerabilities
| CVE | Vulnerability type | Affected component |
|---|---|---|
| CVE-2026-79282 | Use-after-free | ANGLE |
| CVE-2026-79290 | Use-after-free | Aura |
| CVE-2026-79054 | Use-after-free | Chromecast |
| CVE-2026-79121 | Improper input validation | Chromecast |
| CVE-2026-79224 | Use-after-free | Chromecast |
| CVE-2026-79052 | Use-after-free | Aura |
| CVE-2026-79150 | Use-after-free | Views |
| CVE-2026-78935 | Use of uninitialized variable | Mobile |
| CVE-2026-79012 | Use-after-free | Safe Browsing |
| CVE-2026-79200 | Use-after-free | Aura |
The update also contains a large set of high-severity fixes affecting ANGLE, WebGL, V8, WebRTC, Extensions, Autofill, GPU, Bluetooth, Sandbox, Passwords, and other browser subsystems.
High-severity bugs include buffer overflows, out-of-bounds reads and writes, type-confusion errors, authorization flaws, race conditions, and information leaks.
Several high-severity fixes concern ANGLE, including out-of-bounds writes, buffer overflows, type confusion, use-after-free conditions, and uninitialized resources.
Since ANGLE processes graphics-related content, malicious web pages could potentially use specially crafted graphics or WebGL data to reach vulnerable browser code.
Google has not said that any of the fixed vulnerabilities are being actively exploited in attacks. However, the company is temporarily restricting access to bug details and links until most users have updated.
Google may also retain restrictions when a flaw in a third-party library has not yet been fixed in other dependent projects. Users should update Chrome immediately by opening the browser menu, navigating to Help, selecting About Google Chrome, and relaunching after the update downloads.
Organizations should verify that managed endpoints update to Chrome 152 as it becomes available through their established update channels.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC