Critical New Google Security Update—127 Chrome Security Vulnerabilities Confirmed
There’s nothing unusual about Google issuing updates for the world’s most popular web browser, but when that update is a result of an astonishing 127 security flaws, you need to pay attention. While the last security update fixed a total of 30 security vulnerabilities, three of which were critical, the fact that the latest drop includes one fewer critical vulnerability is rather moot given the sheer volume being addressed here. Google has also confirmed that the update to Chrome 148.0.7778.96/97 will start rolling out “over the coming days/weeks,” so you should take action now to ensure you are protected rather than waiting for the automatic process to eventually kick in. Here’s what you need to know and do.
What You Need To Know About The Google Chrome 148.0.7778.96/97 Security Update
It has already been quite the week for Google updates, what with the confirmation of a critical zero-click vulnerability impacting users of Android 14, Android 15, Android 16, and Android 16-QPR2 operating systems. But this latest news, announced by Google Chrome’s Srinivas Sista, is the icing on the security cake. “The Chrome team is delighted to announce the promotion of Chrome 148 to the stable channel for Windows, Mac and Linux,” Sista said, before adding that the release also “includes 127 security fixes.”
To be honest, I am more used to reporting this kind of vulnerability volume when it is Patch Tuesday and we are talking Windows security updates. But here we are with Google reaching the same kind of high numbers for a single Chrome release. Whether this is partly to do with the increasing use of AI tools in the vulnerability hunting process is not clear. What is crystal, however, is that with three of the vulnerabilities given a Common Vulnerability Scoring System severity rating of critical, and 31 high-rated, you cannot afford to ignore this one.
Google has confirmed that the critical vulnerabilities are as follows:
CVE-2026-7896: Integer overflow in Blink. CVE-2026-7897: Use after free in Mobile. CVE-2026-7898: Use after free in Chromoting.
The first of these earning the security researcher who disclosed it to Google a staggering $43,000 bug bounty payment .
You can check the original posting for the basic details of all the vulnerabilities that have been fixed, although Google withholds technical details until the majority of Chrome users have been able to update the web browser.
Summary: Google Chrome 148 Security Update
With Google having now confirmed 127 security vulnerabilities impacting its web browser, at the same time, admitting that the critical update to fix these will roll out across the coming days or weeks, it is vital for all users to ensure they act as soon as possible to stay protected. Do not wait for the automatic update to finally reach you; instead, head to the three-dot menu in your browser and select Help|About Google Chrome, which will kickstart the update process right away.
Loading article...