Point-in-time editing now available in Google Vids

Google Vids is improving the video creation experience with the introduction of point-in-time editing. This feature will help ensure that the canvas matches the video timeline 1:1. Previously, the canvas displayed all elements present across an entire scene all at the same time, regardless of when they appeared during the video. With this update, when a user is editing, they will see exactly what appears in the video at that specific timestamp, eliminating visual clutter from overlapping text boxes, stickers, and images.

This update simplifies the creation process by providing a true "what you see is what you get" editing workflow. Key improvements include:

  • Synchronized canvas display: The editing canvas dynamically updates as you scrub or move through the timeline, showing only the active elements at that exact moment.
  • Enhanced timeline interaction: Editors can click directly on object tracks within the timeline to move the playhead to that point.
  • Simplified scene management: Users no longer need to split scenes into smaller segments simply to manage multiple timed objects, making it easier to build multi-layered content like captions, lower thirds, and media overlays.

Point-in-time editing is the default behavior across all Google Vids sessions and requires no action from administrators. This streamlined experience will help users create polished video content more efficiently without managing overlapping elements.



Point-in-time editing in Google Vids

Getting started

  • Admins: There is no admin control for this feature.
  • End users: There is no end user setting for this feature. Visit the Help Center to learn more.

Rollout pace

Availability

  • Business: Business Starter, Standard, Plus and Base
  • Enterprise: Enterprise Starter, Standard, and Plus
  • Education: Education Fundamentals, Standard, and Plus
  • Consumer: Google AI Plus and Ultra
  • Other Editions: Frontline Starter, Standard, and Plus; Essentials Starter, Enterprise Essentials, and Enterprise Essentials Plus; Individual; Nonprofits
  • Education Add-ons: Google AI Pro for Education; Teaching and Learning
  • Other Add-ons: AI Expanded Access

Resources

Create Trello cards from Google Chat messages with Trello for Google Workspace

Trello for Google Workspace makes it easy to capture tasks and ideas from the conversations where they begin. With the app, you can create new Trello cards from emails and Google Chat messages, helping you keep Trello up to date without switching tabs or breaking your flow.

The refreshed app replaces and builds on the Trello for Gmail experience and adds the ability to create new cards from Google Chat. Existing Trello for Gmail users can continue using the app without reinstalling or reauthorizing it. To create cards from Google Chat, add Trello for Google Workspace to a Chat space or direct message and follow the sign-in prompt.


Getting started

Rollout pace

Availability

  • Available to all Google Workspace customers and users with personal Google accounts. Requires a Trello account to use.

Resources

Stable Channel Update for Desktop

The Stable channel has been updated to 155.0.8059.39/.40 for Windows and Mac and 155.0.8059.39 to Linux which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.


This update includes 247 security fixes. Please see the Chrome Security Page for more information.


[N/A][534994449] Critical CVE-2026-106382: Use after free in Chromecast. Reported by Google on 2026-07-15


[TBD][560238696] Critical CVE-2026-106197: Use after free in Browser. Reported by Xinyang Ge on 2026-09-11


[TBD][567160164] Critical CVE-2026-106358: Use after free in Navigation. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-28


[N/A][567936270] Critical CVE-2026-106347: Use after free in Track. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-30


[$5000][527023137] High CVE-2026-102322: Incorrect Authorization in SiteIsolation. Reported by Avadhut Mahamuni on 2026-06-23


[$2,000][550302121] High CVE-2026-106245: Uninitialized resource in ANGLE. Reported by JonathanBouman on 2026-08-21


[$2,000][551529559] High CVE-2026-106327: Incorrect authorization in Core. Reported by OGINOME Tomohito on 2026-08-23


[$2,000][552115620] High CVE-2026-106366: Incomplete cleanup in CustomTabs. Reported by Naoya Miyaguchi on 2026-08-24


[$2,000][553857574] High CVE-2026-106258: Uninitialized resource in ANGLE. Reported by weihengqiuu on 2026-08-28


[$2,000][553881031] High CVE-2026-106376: Uninitialized resource in ANGLE. Reported by weihengqiuu on 2026-08-28


[$2,000][560055258] High CVE-2026-106308: Incorrect reference resolution in Autofill. Reported by Anonymous on 2026-09-11


[$2,000][561066220] High CVE-2026-106215: Uninitialized resource in ANGLE. Reported by JonathanBouman on 2026-09-13


[$1,000][539043243] High CVE-2026-106369: Missing authorization in Translate. Reported by M. Fauzan Wijaya (Gh05t666nero) on 2026-07-26


[$1,000][547343108] High CVE-2026-106293: Type confusion in ANGLE. Reported by Jinpyo Lee on 2026-08-16


[N/A][520179149] High CVE-2026-106377: Race condition in Fonts. Reported by Google on 2026-06-05


[N/A][520755056] High CVE-2026-106412: Race condition in Core. Reported by Google on 2026-06-06


[N/A][533426590] High CVE-2026-106243: Incomplete cleanup in Proxy Auth. Reported by Google on 2026-07-10


[N/A][533493992] High CVE-2026-106214: Information leak in Proxy. Reported by Google on 2026-07-10


[N/A][540018068] High CVE-2026-106364: Incorrect authorization in Omnibox. Reported by Google on 2026-07-28


[N/A][546630009] High CVE-2026-106239: Integer overflow in WebGL. Reported by Google on 2026-08-14


[TBD][547065823] High CVE-2026-106426: Race condition in Fonts. Reported by Emond Papegaaij on 2026-08-17


[TBD][550379413] High CVE-2026-106419: Use after free in ANGLE. Reported by Shaked Reiner (Palo Alto Networks) on 2026-08-21


[N/A][552423127] High CVE-2026-106396: Improper input validation in Omnibox. Reported by Google on 2026-08-25


[N/A][553114676] High CVE-2026-106323: Missing authorization in Chrome for iOS. Reported by Google on 2026-08-26


[N/A][553115993] High CVE-2026-106231: Uninitialized resource in Dawn. Reported by Google on 2026-08-26


[N/A][553117809] High CVE-2026-106202: Uninitialized resource in ANGLE. Reported by Google on 2026-08-26


[N/A][553118338] High CVE-2026-106273: Uninitialized resource in Video. Reported by Google on 2026-08-26


[TBD][553394296] High CVE-2026-106203: Incomplete cleanup in Autofill. Reported by Anonymous on 2026-08-27


[N/A][553454734] High CVE-2026-106332: Integer overflow in Compositing. Reported by Google on 2026-08-27


[TBD][554992296] High CVE-2026-106281: Use after free in Tint. Reported by 0599jiangyc on 2026-08-31


[TBD][555932520] High CVE-2026-106298: Use after free in Chrome Tabs. Reported by TIENPA on 2026-09-02


[TBD][557729858] High CVE-2026-106193: Use after free in Parser. Reported by Blockian Creator of Kritt and Open-Kritt on 2026-09-05


[N/A][559780376] High CVE-2026-106255: Race condition in V8. Reported by Google on 2026-09-10


[TBD][559793873] High CVE-2026-106393: Use after free in Storage. Reported by Xinyang Ge on 2026-09-10


[N/A][561891645] High CVE-2026-106227: Use after free in Core. Reported by Google on 2026-09-15


[N/A][561987051] High CVE-2026-106379: Uninitialized resource in Skia. Reported by Google on 2026-09-15


[N/A][562002095] High CVE-2026-106211: Use after free in TabStrip. Reported by Google on 2026-09-15


[N/A][562043997] High CVE-2026-106329: Incorrect authorization in FileSystem. Reported by Google on 2026-09-15


[TBD][563673584] High CVE-2026-106248: Use after free in Bindings. Reported by Alessandro Rizzo (0xAlessandro) on 2026-09-19


[TBD][565612897] High CVE-2026-106235: Use after free in WebAudio. Reported by Team Allied (Hyeongeun Ji, h4nk3r1n, h4vrut4, HunSec, nag0x) on 2026-09-24


[TBD][565674529] High CVE-2026-106257: Use after free in HTML. Reported by OpenAI Codex Security (amyb) on 2026-09-24


[TBD][565742177] High CVE-2026-106268: Use after free in WebRTC. Reported by xinyang on 2026-09-24


[TBD][565774991] High CVE-2026-106278: Use after free in Select. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-24


[TBD][565797213] High CVE-2026-106233: Use after free in Metrics. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-24


[TBD][566111249] High CVE-2026-106318: Use after free in Media. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-25


[TBD][566136674] High CVE-2026-106411: Use after free in Parser. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-25


[TBD][566347711] High CVE-2026-106423: Use after free in Media. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-26


[N/A][566404364] High CVE-2026-106346: Improper state validation in DevTools. Reported by Google on 2026-09-26


[TBD][566824998] High CVE-2026-106190: Use after free in Media. Reported by weihengqiuu on 2026-09-27


[TBD][567160162] High CVE-2026-106357: Use after free in WebRTC. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-28


[TBD][567177599] High CVE-2026-106240: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-28


[TBD][567379988] High CVE-2026-106184: Uninitialized resource in Media. Reported by James Burton (Offensive Security @ Meta) on 2026-09-29


[TBD][567447106] High CVE-2026-106383: Use after free in Media. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-29


[TBD][567538973] High CVE-2026-106349: Use after free in V8. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-29


[N/A][567873463] High CVE-2026-106421: Use after free in PDF. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-30


[N/A][567910530] High CVE-2026-106204: Use after free in PDF. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-30


[N/A][568422505] High CVE-2026-106200: Use after free in Track. Reported by Google on 2026-10-01


[$3,000][380789337] Medium CVE-2026-106265: UI misrepresentation in File. Reported by Umar Farooq on 2024-11-25


[$3,000][492374387] Medium CVE-2026-106238: Race condition in Fonts. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-13


[$2,000][501171258] Medium CVE-2026-106324: Incorrect authorization in WebAppInstalls. Reported by Narenda Singh (@_3P1C) on 2026-04-09


[$1,000][477327257] Medium CVE-2026-106420: Incorrect calculation in API. Reported by Luan Herrera (@lbherrera_) on 2026-01-21


[N/A][496623893] Medium CVE-2026-106222: Incorrect authorization in Sync. Reported by Google on 2026-03-26


[N/A][497062057] Medium CVE-2026-106208: Missing authorization in API. Reported by Google on 2026-03-28


[N/A][497148613] Medium CVE-2026-106286: Confused deputy in Omnibox. Reported by Google on 2026-03-28


[N/A][497350668] Medium CVE-2026-106181: Incorrect reference resolution in DevTools. Reported by Google on 2026-03-29


[N/A][497652727] Medium CVE-2026-106315: Use after free in Modularization. Reported by Google on 2026-03-30


[N/A][497842821] Medium CVE-2026-106274: Incorrect reference resolution in Browser. Reported by Google on 2026-03-30


[N/A][498075038] Medium CVE-2026-106365: Missing authorization in Animation. Reported by Google on 2026-03-31


[N/A][498737756] Medium CVE-2026-106267: Missing authorization in Network. Reported by Google on 2026-04-01


[N/A][498739277] Medium CVE-2026-106194: Missing authorization in WebAppInstalls. Reported by Google on 2026-04-01


[N/A][498770931] Medium CVE-2026-106313: Incorrect authorization in Browser. Reported by Google on 2026-04-02


[N/A][499468981] Medium CVE-2026-106283: Use after free in Streaming. Reported by Google on 2026-04-04


[N/A][499571442] Medium CVE-2026-106291: Use after free in GarbageCollection. Reported by Google on 2026-04-04


[N/A][500106110] Medium CVE-2026-106300: Race condition in CacheStorage. Reported by Google on 2026-04-06


[N/A][501533684] Medium CVE-2026-106314: Incorrect authorization in Bluetooth. Reported by Google on 2026-04-10


[N/A][501633302] Medium CVE-2026-106223: Uninitialized resource in GPU. Reported by Google on 2026-04-11


[N/A][501647772] Medium CVE-2026-106242: Information leak in Omnibox. Reported by Google on 2026-04-11


[N/A][501729675] Medium CVE-2026-106241: Incorrect authorization in Search. Reported by Google on 2026-04-11


[N/A][501763586] Medium CVE-2026-106381: Incorrect authorization in Passwords. Reported by Google on 2026-04-11


[N/A][501770489] Medium CVE-2026-106217: Missing authorization in Google Lens. Reported by Google on 2026-04-12


[N/A][501790682] Medium CVE-2026-106425: Missing authorization in BrowserTag. Reported by Google on 2026-04-12


[N/A][501805355] Medium CVE-2026-106225: Missing authorization in Autofill. Reported by Google on 2026-04-12


[N/A][501896592] Medium CVE-2026-106363: Missing authorization in FullScreen. Reported by Google on 2026-04-12


[N/A][501914204] Medium CVE-2026-106266: Confused deputy in Contextual Tasks. Reported by Google on 2026-04-12


[N/A][502034469] Medium CVE-2026-106189: Code injection in ReaderMode. Reported by Google on 2026-04-13


[N/A][502105238] Medium CVE-2026-106335: Use after free in Media. Reported by Google on 2026-04-13


[N/A][502179715] Medium CVE-2026-106415: Information leak in Enterprise. Reported by Google on 2026-04-13


[N/A][502278429] Medium CVE-2026-106224: Missing authorization in Google Lens. Reported by Google on 2026-04-13


[N/A][502462485] Medium CVE-2026-106185: Improper input validation in Viz. Reported by Google on 2026-04-14


[N/A][502475175] Medium CVE-2026-106244: Incorrect authorization in Permissions. Reported by Google on 2026-04-14


[N/A][502648640] Medium CVE-2026-106407: Incorrect authorization in GetUserMedia. Reported by Google on 2026-04-14


[N/A][503625361] Medium CVE-2026-106389: Incorrect authorization in USB. Reported by Google on 2026-04-17


[N/A][503725788] Medium CVE-2026-106397: Incorrect authorization in Mobile. Reported by Google on 2026-04-17


[N/A][504215649] Medium CVE-2026-106196: Missing authorization in Navigation. Reported by Google on 2026-04-19


[N/A][504223609] Medium CVE-2026-106414: Improper input validation in Mobile. Reported by Google on 2026-04-19


[N/A][504227656] Medium CVE-2026-106408: Protection mechanism failure in Mobile. Reported by Google on 2026-04-19


[N/A][504638005] Medium CVE-2026-106261: Uninitialized resource in Video. Reported by Google on 2026-04-20


[N/A][505186109] Medium CVE-2026-106406: Missing authorization in Mobile. Reported by Google on 2026-04-22


[N/A][507351786] Medium CVE-2026-106290: Uninitialized resource in GPU. Reported by Google on 2026-04-28


[TBD][507596239] Medium CVE-2026-106378: Privilege elevation in Sandbox. Reported by Paulos Yibelo Mesfin on 2026-04-29


[TBD][510773353] Medium CVE-2026-106198: Missing authorization in FileSystem. Reported by pakhunov.anton.n on 2026-05-07


[N/A][511745101] Medium CVE-2026-106326: Confused deputy in UI. Reported by Google on 2026-05-10


[N/A][511796554] Medium CVE-2026-106354: Improper resource exposure in Extensions. Reported by Google on 2026-05-10


[N/A][512998592] Medium CVE-2026-106342: Information leak in Autofill. Reported by Google on 2026-05-13


[N/A][513365978] Medium CVE-2026-106424: Information leak in Audio. Reported by Google on 2026-05-15


[N/A][513741326] Medium CVE-2026-106253: Incorrect authorization in Extensions. Reported by Google on 2026-05-16


[N/A][513757840] Medium CVE-2026-106279: Incorrect reference resolution in Passwords. Reported by Google on 2026-05-16


[N/A][513781133] Medium CVE-2026-106361: Incorrect provision of specified functionality in Mobile. Reported by Google on 2026-05-16


[N/A][514041626] Medium CVE-2026-106402: Incorrect authorization in Extensions. Reported by Google on 2026-05-17


[N/A][514061289] Medium CVE-2026-106311: Clickjacking in PermissionElement. Reported by Google on 2026-05-17


[N/A][514070956] Medium CVE-2026-106246: Incorrect authorization in Browser. Reported by Google on 2026-05-17


[N/A][514071472] Medium CVE-2026-106302: UI misrepresentation in PermissionElement. Reported by Google on 2026-05-17


[N/A][514072462] Medium CVE-2026-106416: Code injection in Extensions. Reported by Google on 2026-05-17


[N/A][514078734] Medium CVE-2026-106182: UI misrepresentation in Paint. Reported by Google on 2026-05-17


[N/A][514204338] Medium CVE-2026-106282: UI misrepresentation in WebOTP. Reported by Google on 2026-05-18


[N/A][514426571] Medium CVE-2026-106392: Information leak in WebAudio. Reported by Google on 2026-05-18


[N/A][515477538] Medium CVE-2026-106188: Confused deputy in SignIn. Reported by Google on 2026-05-21


[N/A][517033396] Medium CVE-2026-106370: Uninitialized resource in GPU. Reported by Google on 2026-05-27


[N/A][517090646] Medium CVE-2026-106356: Clickjacking in EVP. Reported by Google on 2026-05-27


[N/A][517150523] Medium CVE-2026-106405: Race condition in CustomTabs. Reported by Google on 2026-05-27


[N/A][517213220] Medium CVE-2026-106322: Open redirect in AppManifest. Reported by Google on 2026-05-27


[N/A][517366426] Medium CVE-2026-106280: Incorrect authorization in PermissionElement. Reported by Google on 2026-05-28


[N/A][517374100] Medium CVE-2026-106206: Improper input validation in Mobile. Reported by Google on 2026-05-28


[N/A][517429254] Medium CVE-2026-106180: Observable discrepancy in Animation. Reported by Google on 2026-05-28


[N/A][517475258] Medium CVE-2026-106303: Observable discrepancy in Autofill AI. Reported by Google on 2026-05-28


[N/A][517546096] Medium CVE-2026-106201: Race condition in V8. Reported by Google on 2026-05-28


[N/A][517649552] Medium CVE-2026-106333: Incorrect authorization in Input. Reported by Google on 2026-05-28


[N/A][517689673] Medium CVE-2026-106228: Confused deputy in Google Lens. Reported by Google on 2026-05-29


[N/A][517700327] Medium CVE-2026-106289: Missing authorization in FedCM. Reported by Google on 2026-05-29


[N/A][517708426] Medium CVE-2026-106277: Information leak in Animation. Reported by Google on 2026-05-29


[N/A][517801814] Medium CVE-2026-106410: Missing authorization in Permissions. Reported by Google on 2026-05-29


[N/A][517804731] Medium CVE-2026-106284: Out of bounds read in Printing. Reported by Google on 2026-05-29


[N/A][518039724] Medium CVE-2026-106209: UI misrepresentation in Mobile. Reported by Google on 2026-05-29


[N/A][518076654] Medium CVE-2026-106216: Cross-site request forgery in ReadingList. Reported by Google on 2026-05-30


[N/A][518091868] Medium CVE-2026-106328: Incorrect authorization in PDF. Reported by Google on 2026-05-30


[N/A][518096516] Medium CVE-2026-106387: Missing authorization in Mobile. Reported by Google on 2026-05-30


[N/A][518108937] Medium CVE-2026-106400: Clickjacking in Messages. Reported by Google on 2026-05-30


[N/A][519499907] Medium CVE-2026-106205: Missing authorization in Passwords. Reported by Google on 2026-06-03


[N/A][520153320] Medium CVE-2026-106213: Race condition in WebAudio. Reported by Google on 2026-06-05


[N/A][520507737] Medium CVE-2026-106230: Incorrect reference resolution in Offline. Reported by Google on 2026-06-05


[N/A][520533412] Medium CVE-2026-106367: Missing authorization in Mobile. Reported by Google on 2026-06-05


[N/A][520573237] Medium CVE-2026-106226: Improper input validation in Compositing. Reported by Google on 2026-06-06


[N/A][521949525] Medium CVE-2026-106229: UI misrepresentation in FileSystem. Reported by Google on 2026-06-09


[N/A][522299740] Medium CVE-2026-106232: UI misrepresentation in Browser. Reported by Google on 2026-06-10


[N/A][522325665] Medium CVE-2026-106391: Incorrect authorization in WebShare. Reported by Google on 2026-06-10


[N/A][522722456] Medium CVE-2026-106336: Observable discrepancy in Paint. Reported by Google on 2026-06-11


[N/A][523601696] Medium CVE-2026-106403: Incorrect authorization in Accessibility. Reported by Google on 2026-06-13


[N/A][523699645] Medium CVE-2026-106373: Use after free in Fonts. Reported by Google on 2026-06-13


[N/A][523750306] Medium CVE-2026-106301: Confused deputy in Contextual Tasks. Reported by Google on 2026-06-14


[N/A][524587778] Medium CVE-2026-106292: Buffer overflow in Fonts. Reported by Google on 2026-06-16


[N/A][533066295] Medium CVE-2026-106262: Incomplete cleanup in GetUserMedia. Reported by Google on 2026-07-09


[TBD][535639435] Medium CVE-2026-106360: Information leak in Payments. Reported by NH DEV on 2026-07-17


[N/A][536507840] Medium CVE-2026-106375: Incomplete cleanup in Dawn. Reported by Google on 2026-07-19


[N/A][537107728] Medium CVE-2026-106348: Information leak in Animation. Reported by Google on 2026-07-21


[N/A][537832408] Medium CVE-2026-106307: Incorrect authorization in Network. Reported by Google on 2026-07-22


[N/A][540072162] Medium CVE-2026-106212: Incorrect authorization in Autofill. Reported by Google on 2026-07-28


[TBD][543082212] Medium CVE-2026-106398: Incorrect authorization in Media. Reported by caveeroo on 2026-08-05


[N/A][550512266] Medium CVE-2026-106388: Missing authorization in DataTransfer. Reported by leolee on 2026-08-21


[N/A][553118313] Medium CVE-2026-106271: Missing authorization in Workers. Reported by Google on 2026-08-26


[N/A][553121488] Medium CVE-2026-106395: Uninitialized resource in Dawn. Reported by Google on 2026-08-26


[N/A][553124799] Medium CVE-2026-106304: Out of bounds read in ANGLE. Reported by Google on 2026-08-26


[N/A][553129739] Medium CVE-2026-106401: Out of bounds write in Media. Reported by Google on 2026-08-26


[N/A][553135213] Medium CVE-2026-106330: Information leak in Paint. Reported by Google on 2026-08-26


[N/A][553138969] Medium CVE-2026-106295: Incorrect authorization in Unbounded Element. Reported by Google on 2026-08-26


[N/A][553139506] Medium CVE-2026-106352: Incorrect authorization in WebProtect. Reported by Google on 2026-08-26


[N/A][553145497] Medium CVE-2026-106337: UI misrepresentation in UI. Reported by Google on 2026-08-26


[N/A][553149001] Medium CVE-2026-106263: Improper input validation in SignIn. Reported by Google on 2026-08-26


[N/A][553150261] Medium CVE-2026-106404: Incorrect authorization in FontAccess. Reported by Google on 2026-08-26


[N/A][553154579] Medium CVE-2026-106183: Missing authorization in Chromoting. Reported by Google on 2026-08-26


[N/A][553156221] Medium CVE-2026-106386: Uninitialized resource in WebAudio. Reported by Google on 2026-08-26


[N/A][553164077] Medium CVE-2026-106351: Observable discrepancy in Safebrowsing. Reported by Google on 2026-08-27


[TBD][554348119] Medium CVE-2026-106384: Missing authorization in SiteIsolation. Reported by med.bassia on 2026-08-29


[TBD][554619028] Medium CVE-2026-106207: Race condition in V8. Reported by flyyy on 2026-08-30


[N/A][556235808] Medium CVE-2026-106321: Information leak in Editing. Reported by Google on 2026-09-02


[TBD][556304559] Medium CVE-2026-106210: Observable discrepancy in Scroll. Reported by Hafiizh on 2026-09-03


[TBD][557036053] Medium CVE-2026-106254: Information leak in Mobile. Reported by Anonymous on 2026-09-04


[TBD][557288890] Medium CVE-2026-106372: Incorrect authorization in UI. Reported by Quyen Son at VinFast (@zer0qs) on 2026-09-05


[N/A][558539954] Medium CVE-2026-106341: Type confusion in V8. Reported by Google on 2026-09-08


[TBD][559097675] Medium CVE-2026-106409: Incorrect reference resolution in WebAppInstalls. Reported by Quyen Son at VinFast (@zer0qs) on 2026-09-09


[$2,000][503794852] Low CVE-2026-106340: Missing authorization in CredentialProvider. Reported by Wooseok Sung on 2026-04-17


[$1,000][417555081] Low CVE-2026-106276: UI misrepresentation in Payments. Reported by Khalil Zhani on 2025-05-14


[TBD][448789663] Low CVE-2026-106338: UI misrepresentation in PictureInPicture. Reported by Hafiizh on 2025-10-02


[TBD][450323465] Low CVE-2026-106317: UI misrepresentation in FullScreen. Reported by Manojkumar Jaganathan (https://www.linkedin.com/in/manojkumar-j-7ba35b202/) Aka TheWhiteEvil (https://hackerone.com/the-white-evil) with HackerBro Technologies on 2025-10-09


[N/A][498375898] Low CVE-2026-106344: Missing authorization in Permissions. Reported by Google on 2026-04-01


[N/A][500532594] Low CVE-2026-106359: Confused deputy in DeviceBoundSessionCredentials. Reported by Google on 2026-04-08


[N/A][502078791] Low CVE-2026-106353: Improper input validation in Mobile. Reported by Google on 2026-04-13


[N/A][502111211] Low CVE-2026-106312: Missing authorization in SignIn. Reported by Google on 2026-04-13


[N/A][502282293] Low CVE-2026-106191: Missing authorization in Actor. Reported by Google on 2026-04-13


[N/A][502497790] Low CVE-2026-106250: Missing authorization in Actor. Reported by Google on 2026-04-14


[TBD][503708636] Low CVE-2026-106309: Incorrect authorization in Selection. Reported by Putra Mahardika | Instagram @mhrdkaa._ on 2026-04-17


[N/A][511776800] Low CVE-2026-106187: Missing authorization in Permissions. Reported by Google on 2026-05-10


[N/A][513122002] Low CVE-2026-106394: Incomplete cleanup in Glic. Reported by Project Fortify on 2026-05-14


[N/A][513383360] Low CVE-2026-106306: Incorrect authorization in DevTools. Reported by Google on 2026-05-15


[N/A][513423334] Low CVE-2026-106427: Confused deputy in Mobile. Reported by Google on 2026-05-15


[N/A][513446410] Low CVE-2026-106252: Incorrect comparison in Fonts. Reported by Google on 2026-05-15


[N/A][513518289] Low CVE-2026-106287: Information loss in CORS. Reported by Google on 2026-05-15


[N/A][513735469] Low CVE-2026-106297: Incorrect authorization in Scheduling. Reported by Google on 2026-05-16


[N/A][513821237] Low CVE-2026-106260: Incorrect authorization in DevTools. Reported by Google on 2026-05-16


[N/A][514456975] Low CVE-2026-106362: Missing authorization in DevTools. Reported by Google on 2026-05-19


[N/A][514460295] Low CVE-2026-106275: Uninitialized resource in GPU. Reported by Google on 2026-05-19


[N/A][517703787] Low CVE-2026-106199: Incorrect authorization in Actor. Reported by Google on 2026-05-29


[N/A][519211890] Low CVE-2026-106299: Improper input validation in WebAudio. Reported by Google on 2026-06-02


[N/A][519458746] Low CVE-2026-106422: Incorrect authorization in API. Reported by Google on 2026-06-03


[N/A][522557469] Low CVE-2026-106186: Uncontrolled search path element in CredentialProvider. Reported by Google on 2026-06-11


[N/A][524435922] Low CVE-2026-106247: Buffer overflow in ANGLE. Reported by Google on 2026-06-16


[N/A][524681280] Low CVE-2026-106192: Information leak in Mobile. Reported by Google on 2026-06-16


[N/A][530237174] Low CVE-2026-106399: Out of bounds read in Skia. Reported by Google on 2026-07-01


[N/A][533084756] Low CVE-2026-106264: Missing authorization in Web Authentication (Passkeys & Security Keys). Reported by Google on 2026-07-09


[N/A][533119681] Low CVE-2026-106285: UI misrepresentation in WebAppInstalls. Reported by Google on 2026-07-09


[N/A][534843648] Low CVE-2026-106220: Information leak in Passwords. Reported by Google on 2026-07-14


[N/A][536471438] Low CVE-2026-106417: Integer overflow in Media. Reported by Google on 2026-07-19


[N/A][540049672] Low CVE-2026-106221: Confused deputy in WebAPKs. Reported by Google on 2026-07-28


[N/A][540076586] Low CVE-2026-106259: Incorrect authorization in PermissionElement. Reported by Google on 2026-07-28


[N/A][540078886] Low CVE-2026-106296: Improper privilege management in UI. Reported by Google on 2026-07-28


[TBD][552440317] Low CVE-2026-106249: Incorrect authorization in Autofill. Reported by mute1008 on 2026-08-25


[TBD][552832446] Low CVE-2026-106374: Type confusion in V8. Reported by SecBuddyN, Tencent KeenLab (CodeBuddy Security) on 2026-08-26


[N/A][553168380] Low CVE-2026-106380: UI misrepresentation in UI. Reported by Google on 2026-08-27


[N/A][553250818] Low CVE-2026-106179: UI misrepresentation in WebAppInstalls. Reported by Google on 2026-08-27


[N/A][553252261] Low CVE-2026-106368: UI misrepresentation in UI. Reported by Google on 2026-08-27


[N/A][553255283] Low CVE-2026-106237: Information leak in Permissions. Reported by Google on 2026-08-27


[N/A][553256068] Low CVE-2026-106331: Improper input validation in Extensions. Reported by Google on 2026-08-27


[N/A][553269860] Low CVE-2026-106270: Incorrect authorization in WebAppInstalls. Reported by Google on 2026-08-27


[N/A][553270559] Low CVE-2026-106350: Incorrect authorization in Browser. Reported by Google on 2026-08-27


[N/A][553274076] Low CVE-2026-106288: Missing authorization in Browser. Reported by Google on 2026-08-27


[N/A][553276352] Low CVE-2026-106305: UI misrepresentation in Mobile. Reported by Google on 2026-08-27


[N/A][553283471] Low CVE-2026-106418: Missing authorization in Network. Reported by Google on 2026-08-27


[N/A][553317583] Low CVE-2026-106343: Improper state validation in Autofill AI. Reported by Google on 2026-08-27


[N/A][553326010] Low CVE-2026-106371: Incorrect authorization in Transactions Platform. Reported by Google on 2026-08-27


[N/A][553335319] Low CVE-2026-106256: Information leak in Passwords. Reported by Google on 2026-08-27


[N/A][553336689] Low CVE-2026-106413: Race condition in Browser. Reported by Google on 2026-08-27


[N/A][553913506] Low CVE-2026-106339: Use of released resource in Core. Reported by Google on 2026-08-28


[N/A][553929758] Low CVE-2026-106320: Use of released resource in UI. Reported by Google on 2026-08-28


[N/A][553930843] Low CVE-2026-106195: Incorrect authorization in Chromoting. Reported by Google on 2026-08-28


[N/A][554556423] Low CVE-2026-106316: UI misrepresentation in Chromoting. Reported by Google on 2026-08-29


[N/A][554874487] Low CVE-2026-106385: Race condition in Chromoting. Reported by Google on 2026-08-30


[N/A][556211265] Low CVE-2026-106325: Incorrect reference resolution in Core. Reported by Google on 2026-09-02


[N/A][556213916] Low CVE-2026-106390: Incorrect provision of specified functionality in SanitizerAPI. Reported by Google on 2026-09-02


[N/A][556215048] Low CVE-2026-106294: Incomplete cleanup in Chromoting. Reported by Google on 2026-09-02


[N/A][556229780] Low CVE-2026-106334: Information leak in Payments. Reported by Google on 2026-09-02


[N/A][556233068] Low CVE-2026-106236: UI misrepresentation in Chromoting. Reported by Google on 2026-09-02


[N/A][556237314] Low CVE-2026-106251: UI misrepresentation in Chromoting. Reported by Google on 2026-09-02


[N/A][556250086] Low CVE-2026-106310: Use of released resource in FontAccess. Reported by Google on 2026-09-02


[N/A][556258544] Low CVE-2026-106345: Use of released resource in Session. Reported by Google on 2026-09-02


[N/A][556259957] Low CVE-2026-106272: UI misrepresentation in Chromoting. Reported by Google on 2026-09-02


[N/A][559777100] Low CVE-2026-106355: Missing authorization in Media. Reported by Google on 2026-09-10


[TBD][564085088] Low CVE-2026-106234: Use after free in Network. Reported by Findingz on 2026-09-20


[TBD][565742178] Low CVE-2026-106269: Use after free in CSS. Reported by xinyang on 2026-09-24


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.

Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.

Daniel Yip

Google Chrome

Stable Channel Update for Desktop

The Stable channel has been updated to 155.0.8059.39/.40 for Windows and Mac and 155.0.8059.39 to Linux which will roll out over the coming days/weeks. A full list of changes in this build is available in the Log

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.


This update includes 247 security fixes. Please see the Chrome Security Page for more information.


[N/A][534994449] Critical CVE-2026-106382: Use after free in Chromecast. Reported by Google on 2026-07-15


[TBD][560238696] Critical CVE-2026-106197: Use after free in Browser. Reported by Xinyang Ge on 2026-09-11


[TBD][567160164] Critical CVE-2026-106358: Use after free in Navigation. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-28


[N/A][567936270] Critical CVE-2026-106347: Use after free in Track. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-30


[$5000][527023137] High CVE-2026-102322: Incorrect Authorization in SiteIsolation. Reported by Avadhut Mahamuni on 2026-06-23


[$2,000][550302121] High CVE-2026-106245: Uninitialized resource in ANGLE. Reported by JonathanBouman on 2026-08-21


[$2,000][551529559] High CVE-2026-106327: Incorrect authorization in Core. Reported by OGINOME Tomohito on 2026-08-23


[$2,000][552115620] High CVE-2026-106366: Incomplete cleanup in CustomTabs. Reported by Naoya Miyaguchi on 2026-08-24


[$2,000][553857574] High CVE-2026-106258: Uninitialized resource in ANGLE. Reported by weihengqiuu on 2026-08-28


[$2,000][553881031] High CVE-2026-106376: Uninitialized resource in ANGLE. Reported by weihengqiuu on 2026-08-28


[$2,000][560055258] High CVE-2026-106308: Incorrect reference resolution in Autofill. Reported by Anonymous on 2026-09-11


[$2,000][561066220] High CVE-2026-106215: Uninitialized resource in ANGLE. Reported by JonathanBouman on 2026-09-13


[$1,000][539043243] High CVE-2026-106369: Missing authorization in Translate. Reported by M. Fauzan Wijaya (Gh05t666nero) on 2026-07-26


[$1,000][547343108] High CVE-2026-106293: Type confusion in ANGLE. Reported by Jinpyo Lee on 2026-08-16


[N/A][520179149] High CVE-2026-106377: Race condition in Fonts. Reported by Google on 2026-06-05


[N/A][520755056] High CVE-2026-106412: Race condition in Core. Reported by Google on 2026-06-06


[N/A][533426590] High CVE-2026-106243: Incomplete cleanup in Proxy Auth. Reported by Google on 2026-07-10


[N/A][533493992] High CVE-2026-106214: Information leak in Proxy. Reported by Google on 2026-07-10


[N/A][540018068] High CVE-2026-106364: Incorrect authorization in Omnibox. Reported by Google on 2026-07-28


[N/A][546630009] High CVE-2026-106239: Integer overflow in WebGL. Reported by Google on 2026-08-14


[TBD][547065823] High CVE-2026-106426: Race condition in Fonts. Reported by Emond Papegaaij on 2026-08-17


[TBD][550379413] High CVE-2026-106419: Use after free in ANGLE. Reported by Shaked Reiner (Palo Alto Networks) on 2026-08-21


[N/A][552423127] High CVE-2026-106396: Improper input validation in Omnibox. Reported by Google on 2026-08-25


[N/A][553114676] High CVE-2026-106323: Missing authorization in Chrome for iOS. Reported by Google on 2026-08-26


[N/A][553115993] High CVE-2026-106231: Uninitialized resource in Dawn. Reported by Google on 2026-08-26


[N/A][553117809] High CVE-2026-106202: Uninitialized resource in ANGLE. Reported by Google on 2026-08-26


[N/A][553118338] High CVE-2026-106273: Uninitialized resource in Video. Reported by Google on 2026-08-26


[TBD][553394296] High CVE-2026-106203: Incomplete cleanup in Autofill. Reported by Anonymous on 2026-08-27


[N/A][553454734] High CVE-2026-106332: Integer overflow in Compositing. Reported by Google on 2026-08-27


[TBD][554992296] High CVE-2026-106281: Use after free in Tint. Reported by 0599jiangyc on 2026-08-31


[TBD][555932520] High CVE-2026-106298: Use after free in Chrome Tabs. Reported by TIENPA on 2026-09-02


[TBD][557729858] High CVE-2026-106193: Use after free in Parser. Reported by Blockian Creator of Kritt and Open-Kritt on 2026-09-05


[N/A][559780376] High CVE-2026-106255: Race condition in V8. Reported by Google on 2026-09-10


[TBD][559793873] High CVE-2026-106393: Use after free in Storage. Reported by Xinyang Ge on 2026-09-10


[N/A][561891645] High CVE-2026-106227: Use after free in Core. Reported by Google on 2026-09-15


[N/A][561987051] High CVE-2026-106379: Uninitialized resource in Skia. Reported by Google on 2026-09-15


[N/A][562002095] High CVE-2026-106211: Use after free in TabStrip. Reported by Google on 2026-09-15


[N/A][562043997] High CVE-2026-106329: Incorrect authorization in FileSystem. Reported by Google on 2026-09-15


[TBD][563673584] High CVE-2026-106248: Use after free in Bindings. Reported by Alessandro Rizzo (0xAlessandro) on 2026-09-19


[TBD][565612897] High CVE-2026-106235: Use after free in WebAudio. Reported by Team Allied (Hyeongeun Ji, h4nk3r1n, h4vrut4, HunSec, nag0x) on 2026-09-24


[TBD][565674529] High CVE-2026-106257: Use after free in HTML. Reported by OpenAI Codex Security (amyb) on 2026-09-24


[TBD][565742177] High CVE-2026-106268: Use after free in WebRTC. Reported by xinyang on 2026-09-24


[TBD][565774991] High CVE-2026-106278: Use after free in Select. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-24


[TBD][565797213] High CVE-2026-106233: Use after free in Metrics. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-24


[TBD][566111249] High CVE-2026-106318: Use after free in Media. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-25


[TBD][566136674] High CVE-2026-106411: Use after free in Parser. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-25


[TBD][566347711] High CVE-2026-106423: Use after free in Media. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-26


[N/A][566404364] High CVE-2026-106346: Improper state validation in DevTools. Reported by Google on 2026-09-26


[TBD][566824998] High CVE-2026-106190: Use after free in Media. Reported by weihengqiuu on 2026-09-27


[TBD][567160162] High CVE-2026-106357: Use after free in WebRTC. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-28


[TBD][567177599] High CVE-2026-106240: Type confusion in V8. Reported by OpenAI Codex Security (amyb) on 2026-09-28


[TBD][567379988] High CVE-2026-106184: Uninitialized resource in Media. Reported by James Burton (Offensive Security @ Meta) on 2026-09-29


[TBD][567447106] High CVE-2026-106383: Use after free in Media. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-29


[TBD][567538973] High CVE-2026-106349: Use after free in V8. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-29


[N/A][567873463] High CVE-2026-106421: Use after free in PDF. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-30


[N/A][567910530] High CVE-2026-106204: Use after free in PDF. Reported by Xinyang Ge (Anthropic), assisted by Claude on 2026-09-30


[N/A][568422505] High CVE-2026-106200: Use after free in Track. Reported by Google on 2026-10-01


[$3,000][380789337] Medium CVE-2026-106265: UI misrepresentation in File. Reported by Umar Farooq on 2024-11-25


[$3,000][492374387] Medium CVE-2026-106238: Race condition in Fonts. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-13


[$2,000][501171258] Medium CVE-2026-106324: Incorrect authorization in WebAppInstalls. Reported by Narenda Singh (@_3P1C) on 2026-04-09


[$1,000][477327257] Medium CVE-2026-106420: Incorrect calculation in API. Reported by Luan Herrera (@lbherrera_) on 2026-01-21


[N/A][496623893] Medium CVE-2026-106222: Incorrect authorization in Sync. Reported by Google on 2026-03-26


[N/A][497062057] Medium CVE-2026-106208: Missing authorization in API. Reported by Google on 2026-03-28


[N/A][497148613] Medium CVE-2026-106286: Confused deputy in Omnibox. Reported by Google on 2026-03-28


[N/A][497350668] Medium CVE-2026-106181: Incorrect reference resolution in DevTools. Reported by Google on 2026-03-29


[N/A][497652727] Medium CVE-2026-106315: Use after free in Modularization. Reported by Google on 2026-03-30


[N/A][497842821] Medium CVE-2026-106274: Incorrect reference resolution in Browser. Reported by Google on 2026-03-30


[N/A][498075038] Medium CVE-2026-106365: Missing authorization in Animation. Reported by Google on 2026-03-31


[N/A][498737756] Medium CVE-2026-106267: Missing authorization in Network. Reported by Google on 2026-04-01


[N/A][498739277] Medium CVE-2026-106194: Missing authorization in WebAppInstalls. Reported by Google on 2026-04-01


[N/A][498770931] Medium CVE-2026-106313: Incorrect authorization in Browser. Reported by Google on 2026-04-02


[N/A][499468981] Medium CVE-2026-106283: Use after free in Streaming. Reported by Google on 2026-04-04


[N/A][499571442] Medium CVE-2026-106291: Use after free in GarbageCollection. Reported by Google on 2026-04-04


[N/A][500106110] Medium CVE-2026-106300: Race condition in CacheStorage. Reported by Google on 2026-04-06


[N/A][501533684] Medium CVE-2026-106314: Incorrect authorization in Bluetooth. Reported by Google on 2026-04-10


[N/A][501633302] Medium CVE-2026-106223: Uninitialized resource in GPU. Reported by Google on 2026-04-11


[N/A][501647772] Medium CVE-2026-106242: Information leak in Omnibox. Reported by Google on 2026-04-11


[N/A][501729675] Medium CVE-2026-106241: Incorrect authorization in Search. Reported by Google on 2026-04-11


[N/A][501763586] Medium CVE-2026-106381: Incorrect authorization in Passwords. Reported by Google on 2026-04-11


[N/A][501770489] Medium CVE-2026-106217: Missing authorization in Google Lens. Reported by Google on 2026-04-12


[N/A][501790682] Medium CVE-2026-106425: Missing authorization in BrowserTag. Reported by Google on 2026-04-12


[N/A][501805355] Medium CVE-2026-106225: Missing authorization in Autofill. Reported by Google on 2026-04-12


[N/A][501896592] Medium CVE-2026-106363: Missing authorization in FullScreen. Reported by Google on 2026-04-12


[N/A][501914204] Medium CVE-2026-106266: Confused deputy in Contextual Tasks. Reported by Google on 2026-04-12


[N/A][502034469] Medium CVE-2026-106189: Code injection in ReaderMode. Reported by Google on 2026-04-13


[N/A][502105238] Medium CVE-2026-106335: Use after free in Media. Reported by Google on 2026-04-13


[N/A][502179715] Medium CVE-2026-106415: Information leak in Enterprise. Reported by Google on 2026-04-13


[N/A][502278429] Medium CVE-2026-106224: Missing authorization in Google Lens. Reported by Google on 2026-04-13


[N/A][502462485] Medium CVE-2026-106185: Improper input validation in Viz. Reported by Google on 2026-04-14


[N/A][502475175] Medium CVE-2026-106244: Incorrect authorization in Permissions. Reported by Google on 2026-04-14


[N/A][502648640] Medium CVE-2026-106407: Incorrect authorization in GetUserMedia. Reported by Google on 2026-04-14


[N/A][503625361] Medium CVE-2026-106389: Incorrect authorization in USB. Reported by Google on 2026-04-17


[N/A][503725788] Medium CVE-2026-106397: Incorrect authorization in Mobile. Reported by Google on 2026-04-17


[N/A][504215649] Medium CVE-2026-106196: Missing authorization in Navigation. Reported by Google on 2026-04-19


[N/A][504223609] Medium CVE-2026-106414: Improper input validation in Mobile. Reported by Google on 2026-04-19


[N/A][504227656] Medium CVE-2026-106408: Protection mechanism failure in Mobile. Reported by Google on 2026-04-19


[N/A][504638005] Medium CVE-2026-106261: Uninitialized resource in Video. Reported by Google on 2026-04-20


[N/A][505186109] Medium CVE-2026-106406: Missing authorization in Mobile. Reported by Google on 2026-04-22


[N/A][507351786] Medium CVE-2026-106290: Uninitialized resource in GPU. Reported by Google on 2026-04-28


[TBD][507596239] Medium CVE-2026-106378: Privilege elevation in Sandbox. Reported by Paulos Yibelo Mesfin on 2026-04-29


[TBD][510773353] Medium CVE-2026-106198: Missing authorization in FileSystem. Reported by pakhunov.anton.n on 2026-05-07


[N/A][511745101] Medium CVE-2026-106326: Confused deputy in UI. Reported by Google on 2026-05-10


[N/A][511796554] Medium CVE-2026-106354: Improper resource exposure in Extensions. Reported by Google on 2026-05-10


[N/A][512998592] Medium CVE-2026-106342: Information leak in Autofill. Reported by Google on 2026-05-13


[N/A][513365978] Medium CVE-2026-106424: Information leak in Audio. Reported by Google on 2026-05-15


[N/A][513741326] Medium CVE-2026-106253: Incorrect authorization in Extensions. Reported by Google on 2026-05-16


[N/A][513757840] Medium CVE-2026-106279: Incorrect reference resolution in Passwords. Reported by Google on 2026-05-16


[N/A][513781133] Medium CVE-2026-106361: Incorrect provision of specified functionality in Mobile. Reported by Google on 2026-05-16


[N/A][514041626] Medium CVE-2026-106402: Incorrect authorization in Extensions. Reported by Google on 2026-05-17


[N/A][514061289] Medium CVE-2026-106311: Clickjacking in PermissionElement. Reported by Google on 2026-05-17


[N/A][514070956] Medium CVE-2026-106246: Incorrect authorization in Browser. Reported by Google on 2026-05-17


[N/A][514071472] Medium CVE-2026-106302: UI misrepresentation in PermissionElement. Reported by Google on 2026-05-17


[N/A][514072462] Medium CVE-2026-106416: Code injection in Extensions. Reported by Google on 2026-05-17


[N/A][514078734] Medium CVE-2026-106182: UI misrepresentation in Paint. Reported by Google on 2026-05-17


[N/A][514204338] Medium CVE-2026-106282: UI misrepresentation in WebOTP. Reported by Google on 2026-05-18


[N/A][514426571] Medium CVE-2026-106392: Information leak in WebAudio. Reported by Google on 2026-05-18


[N/A][515477538] Medium CVE-2026-106188: Confused deputy in SignIn. Reported by Google on 2026-05-21


[N/A][517033396] Medium CVE-2026-106370: Uninitialized resource in GPU. Reported by Google on 2026-05-27


[N/A][517090646] Medium CVE-2026-106356: Clickjacking in EVP. Reported by Google on 2026-05-27


[N/A][517150523] Medium CVE-2026-106405: Race condition in CustomTabs. Reported by Google on 2026-05-27


[N/A][517213220] Medium CVE-2026-106322: Open redirect in AppManifest. Reported by Google on 2026-05-27


[N/A][517366426] Medium CVE-2026-106280: Incorrect authorization in PermissionElement. Reported by Google on 2026-05-28


[N/A][517374100] Medium CVE-2026-106206: Improper input validation in Mobile. Reported by Google on 2026-05-28


[N/A][517429254] Medium CVE-2026-106180: Observable discrepancy in Animation. Reported by Google on 2026-05-28


[N/A][517475258] Medium CVE-2026-106303: Observable discrepancy in Autofill AI. Reported by Google on 2026-05-28


[N/A][517546096] Medium CVE-2026-106201: Race condition in V8. Reported by Google on 2026-05-28


[N/A][517649552] Medium CVE-2026-106333: Incorrect authorization in Input. Reported by Google on 2026-05-28


[N/A][517689673] Medium CVE-2026-106228: Confused deputy in Google Lens. Reported by Google on 2026-05-29


[N/A][517700327] Medium CVE-2026-106289: Missing authorization in FedCM. Reported by Google on 2026-05-29


[N/A][517708426] Medium CVE-2026-106277: Information leak in Animation. Reported by Google on 2026-05-29


[N/A][517801814] Medium CVE-2026-106410: Missing authorization in Permissions. Reported by Google on 2026-05-29


[N/A][517804731] Medium CVE-2026-106284: Out of bounds read in Printing. Reported by Google on 2026-05-29


[N/A][518039724] Medium CVE-2026-106209: UI misrepresentation in Mobile. Reported by Google on 2026-05-29


[N/A][518076654] Medium CVE-2026-106216: Cross-site request forgery in ReadingList. Reported by Google on 2026-05-30


[N/A][518091868] Medium CVE-2026-106328: Incorrect authorization in PDF. Reported by Google on 2026-05-30


[N/A][518096516] Medium CVE-2026-106387: Missing authorization in Mobile. Reported by Google on 2026-05-30


[N/A][518108937] Medium CVE-2026-106400: Clickjacking in Messages. Reported by Google on 2026-05-30


[N/A][519499907] Medium CVE-2026-106205: Missing authorization in Passwords. Reported by Google on 2026-06-03


[N/A][520153320] Medium CVE-2026-106213: Race condition in WebAudio. Reported by Google on 2026-06-05


[N/A][520507737] Medium CVE-2026-106230: Incorrect reference resolution in Offline. Reported by Google on 2026-06-05


[N/A][520533412] Medium CVE-2026-106367: Missing authorization in Mobile. Reported by Google on 2026-06-05


[N/A][520573237] Medium CVE-2026-106226: Improper input validation in Compositing. Reported by Google on 2026-06-06


[N/A][521949525] Medium CVE-2026-106229: UI misrepresentation in FileSystem. Reported by Google on 2026-06-09


[N/A][522299740] Medium CVE-2026-106232: UI misrepresentation in Browser. Reported by Google on 2026-06-10


[N/A][522325665] Medium CVE-2026-106391: Incorrect authorization in WebShare. Reported by Google on 2026-06-10


[N/A][522722456] Medium CVE-2026-106336: Observable discrepancy in Paint. Reported by Google on 2026-06-11


[N/A][523601696] Medium CVE-2026-106403: Incorrect authorization in Accessibility. Reported by Google on 2026-06-13


[N/A][523699645] Medium CVE-2026-106373: Use after free in Fonts. Reported by Google on 2026-06-13


[N/A][523750306] Medium CVE-2026-106301: Confused deputy in Contextual Tasks. Reported by Google on 2026-06-14


[N/A][524587778] Medium CVE-2026-106292: Buffer overflow in Fonts. Reported by Google on 2026-06-16


[N/A][533066295] Medium CVE-2026-106262: Incomplete cleanup in GetUserMedia. Reported by Google on 2026-07-09


[TBD][535639435] Medium CVE-2026-106360: Information leak in Payments. Reported by NH DEV on 2026-07-17


[N/A][536507840] Medium CVE-2026-106375: Incomplete cleanup in Dawn. Reported by Google on 2026-07-19


[N/A][537107728] Medium CVE-2026-106348: Information leak in Animation. Reported by Google on 2026-07-21


[N/A][537832408] Medium CVE-2026-106307: Incorrect authorization in Network. Reported by Google on 2026-07-22


[N/A][540072162] Medium CVE-2026-106212: Incorrect authorization in Autofill. Reported by Google on 2026-07-28


[TBD][543082212] Medium CVE-2026-106398: Incorrect authorization in Media. Reported by caveeroo on 2026-08-05


[N/A][550512266] Medium CVE-2026-106388: Missing authorization in DataTransfer. Reported by leolee on 2026-08-21


[N/A][553118313] Medium CVE-2026-106271: Missing authorization in Workers. Reported by Google on 2026-08-26


[N/A][553121488] Medium CVE-2026-106395: Uninitialized resource in Dawn. Reported by Google on 2026-08-26


[N/A][553124799] Medium CVE-2026-106304: Out of bounds read in ANGLE. Reported by Google on 2026-08-26


[N/A][553129739] Medium CVE-2026-106401: Out of bounds write in Media. Reported by Google on 2026-08-26


[N/A][553135213] Medium CVE-2026-106330: Information leak in Paint. Reported by Google on 2026-08-26


[N/A][553138969] Medium CVE-2026-106295: Incorrect authorization in Unbounded Element. Reported by Google on 2026-08-26


[N/A][553139506] Medium CVE-2026-106352: Incorrect authorization in WebProtect. Reported by Google on 2026-08-26


[N/A][553145497] Medium CVE-2026-106337: UI misrepresentation in UI. Reported by Google on 2026-08-26


[N/A][553149001] Medium CVE-2026-106263: Improper input validation in SignIn. Reported by Google on 2026-08-26


[N/A][553150261] Medium CVE-2026-106404: Incorrect authorization in FontAccess. Reported by Google on 2026-08-26


[N/A][553154579] Medium CVE-2026-106183: Missing authorization in Chromoting. Reported by Google on 2026-08-26


[N/A][553156221] Medium CVE-2026-106386: Uninitialized resource in WebAudio. Reported by Google on 2026-08-26


[N/A][553164077] Medium CVE-2026-106351: Observable discrepancy in Safebrowsing. Reported by Google on 2026-08-27


[TBD][554348119] Medium CVE-2026-106384: Missing authorization in SiteIsolation. Reported by med.bassia on 2026-08-29


[TBD][554619028] Medium CVE-2026-106207: Race condition in V8. Reported by flyyy on 2026-08-30


[N/A][556235808] Medium CVE-2026-106321: Information leak in Editing. Reported by Google on 2026-09-02


[TBD][556304559] Medium CVE-2026-106210: Observable discrepancy in Scroll. Reported by Hafiizh on 2026-09-03


[TBD][557036053] Medium CVE-2026-106254: Information leak in Mobile. Reported by Anonymous on 2026-09-04


[TBD][557288890] Medium CVE-2026-106372: Incorrect authorization in UI. Reported by Quyen Son at VinFast (@zer0qs) on 2026-09-05


[N/A][558539954] Medium CVE-2026-106341: Type confusion in V8. Reported by Google on 2026-09-08


[TBD][559097675] Medium CVE-2026-106409: Incorrect reference resolution in WebAppInstalls. Reported by Quyen Son at VinFast (@zer0qs) on 2026-09-09


[$2,000][503794852] Low CVE-2026-106340: Missing authorization in CredentialProvider. Reported by Wooseok Sung on 2026-04-17


[$1,000][417555081] Low CVE-2026-106276: UI misrepresentation in Payments. Reported by Khalil Zhani on 2025-05-14


[TBD][448789663] Low CVE-2026-106338: UI misrepresentation in PictureInPicture. Reported by Hafiizh on 2025-10-02


[TBD][450323465] Low CVE-2026-106317: UI misrepresentation in FullScreen. Reported by Manojkumar Jaganathan (https://www.linkedin.com/in/manojkumar-j-7ba35b202/) Aka TheWhiteEvil (https://hackerone.com/the-white-evil) with HackerBro Technologies on 2025-10-09


[N/A][498375898] Low CVE-2026-106344: Missing authorization in Permissions. Reported by Google on 2026-04-01


[N/A][500532594] Low CVE-2026-106359: Confused deputy in DeviceBoundSessionCredentials. Reported by Google on 2026-04-08


[N/A][502078791] Low CVE-2026-106353: Improper input validation in Mobile. Reported by Google on 2026-04-13


[N/A][502111211] Low CVE-2026-106312: Missing authorization in SignIn. Reported by Google on 2026-04-13


[N/A][502282293] Low CVE-2026-106191: Missing authorization in Actor. Reported by Google on 2026-04-13


[N/A][502497790] Low CVE-2026-106250: Missing authorization in Actor. Reported by Google on 2026-04-14


[TBD][503708636] Low CVE-2026-106309: Incorrect authorization in Selection. Reported by Putra Mahardika | Instagram @mhrdkaa._ on 2026-04-17


[N/A][511776800] Low CVE-2026-106187: Missing authorization in Permissions. Reported by Google on 2026-05-10


[N/A][513122002] Low CVE-2026-106394: Incomplete cleanup in Glic. Reported by Project Fortify on 2026-05-14


[N/A][513383360] Low CVE-2026-106306: Incorrect authorization in DevTools. Reported by Google on 2026-05-15


[N/A][513423334] Low CVE-2026-106427: Confused deputy in Mobile. Reported by Google on 2026-05-15


[N/A][513446410] Low CVE-2026-106252: Incorrect comparison in Fonts. Reported by Google on 2026-05-15


[N/A][513518289] Low CVE-2026-106287: Information loss in CORS. Reported by Google on 2026-05-15


[N/A][513735469] Low CVE-2026-106297: Incorrect authorization in Scheduling. Reported by Google on 2026-05-16


[N/A][513821237] Low CVE-2026-106260: Incorrect authorization in DevTools. Reported by Google on 2026-05-16


[N/A][514456975] Low CVE-2026-106362: Missing authorization in DevTools. Reported by Google on 2026-05-19


[N/A][514460295] Low CVE-2026-106275: Uninitialized resource in GPU. Reported by Google on 2026-05-19


[N/A][517703787] Low CVE-2026-106199: Incorrect authorization in Actor. Reported by Google on 2026-05-29


[N/A][519211890] Low CVE-2026-106299: Improper input validation in WebAudio. Reported by Google on 2026-06-02


[N/A][519458746] Low CVE-2026-106422: Incorrect authorization in API. Reported by Google on 2026-06-03


[N/A][522557469] Low CVE-2026-106186: Uncontrolled search path element in CredentialProvider. Reported by Google on 2026-06-11


[N/A][524435922] Low CVE-2026-106247: Buffer overflow in ANGLE. Reported by Google on 2026-06-16


[N/A][524681280] Low CVE-2026-106192: Information leak in Mobile. Reported by Google on 2026-06-16


[N/A][530237174] Low CVE-2026-106399: Out of bounds read in Skia. Reported by Google on 2026-07-01


[N/A][533084756] Low CVE-2026-106264: Missing authorization in Web Authentication (Passkeys & Security Keys). Reported by Google on 2026-07-09


[N/A][533119681] Low CVE-2026-106285: UI misrepresentation in WebAppInstalls. Reported by Google on 2026-07-09


[N/A][534843648] Low CVE-2026-106220: Information leak in Passwords. Reported by Google on 2026-07-14


[N/A][536471438] Low CVE-2026-106417: Integer overflow in Media. Reported by Google on 2026-07-19


[N/A][540049672] Low CVE-2026-106221: Confused deputy in WebAPKs. Reported by Google on 2026-07-28


[N/A][540076586] Low CVE-2026-106259: Incorrect authorization in PermissionElement. Reported by Google on 2026-07-28


[N/A][540078886] Low CVE-2026-106296: Improper privilege management in UI. Reported by Google on 2026-07-28


[TBD][552440317] Low CVE-2026-106249: Incorrect authorization in Autofill. Reported by mute1008 on 2026-08-25


[TBD][552832446] Low CVE-2026-106374: Type confusion in V8. Reported by SecBuddyN, Tencent KeenLab (CodeBuddy Security) on 2026-08-26


[N/A][553168380] Low CVE-2026-106380: UI misrepresentation in UI. Reported by Google on 2026-08-27


[N/A][553250818] Low CVE-2026-106179: UI misrepresentation in WebAppInstalls. Reported by Google on 2026-08-27


[N/A][553252261] Low CVE-2026-106368: UI misrepresentation in UI. Reported by Google on 2026-08-27


[N/A][553255283] Low CVE-2026-106237: Information leak in Permissions. Reported by Google on 2026-08-27


[N/A][553256068] Low CVE-2026-106331: Improper input validation in Extensions. Reported by Google on 2026-08-27


[N/A][553269860] Low CVE-2026-106270: Incorrect authorization in WebAppInstalls. Reported by Google on 2026-08-27


[N/A][553270559] Low CVE-2026-106350: Incorrect authorization in Browser. Reported by Google on 2026-08-27


[N/A][553274076] Low CVE-2026-106288: Missing authorization in Browser. Reported by Google on 2026-08-27


[N/A][553276352] Low CVE-2026-106305: UI misrepresentation in Mobile. Reported by Google on 2026-08-27


[N/A][553283471] Low CVE-2026-106418: Missing authorization in Network. Reported by Google on 2026-08-27


[N/A][553317583] Low CVE-2026-106343: Improper state validation in Autofill AI. Reported by Google on 2026-08-27


[N/A][553326010] Low CVE-2026-106371: Incorrect authorization in Transactions Platform. Reported by Google on 2026-08-27


[N/A][553335319] Low CVE-2026-106256: Information leak in Passwords. Reported by Google on 2026-08-27


[N/A][553336689] Low CVE-2026-106413: Race condition in Browser. Reported by Google on 2026-08-27


[N/A][553913506] Low CVE-2026-106339: Use of released resource in Core. Reported by Google on 2026-08-28


[N/A][553929758] Low CVE-2026-106320: Use of released resource in UI. Reported by Google on 2026-08-28


[N/A][553930843] Low CVE-2026-106195: Incorrect authorization in Chromoting. Reported by Google on 2026-08-28


[N/A][554556423] Low CVE-2026-106316: UI misrepresentation in Chromoting. Reported by Google on 2026-08-29


[N/A][554874487] Low CVE-2026-106385: Race condition in Chromoting. Reported by Google on 2026-08-30


[N/A][556211265] Low CVE-2026-106325: Incorrect reference resolution in Core. Reported by Google on 2026-09-02


[N/A][556213916] Low CVE-2026-106390: Incorrect provision of specified functionality in SanitizerAPI. Reported by Google on 2026-09-02


[N/A][556215048] Low CVE-2026-106294: Incomplete cleanup in Chromoting. Reported by Google on 2026-09-02


[N/A][556229780] Low CVE-2026-106334: Information leak in Payments. Reported by Google on 2026-09-02


[N/A][556233068] Low CVE-2026-106236: UI misrepresentation in Chromoting. Reported by Google on 2026-09-02


[N/A][556237314] Low CVE-2026-106251: UI misrepresentation in Chromoting. Reported by Google on 2026-09-02


[N/A][556250086] Low CVE-2026-106310: Use of released resource in FontAccess. Reported by Google on 2026-09-02


[N/A][556258544] Low CVE-2026-106345: Use of released resource in Session. Reported by Google on 2026-09-02


[N/A][556259957] Low CVE-2026-106272: UI misrepresentation in Chromoting. Reported by Google on 2026-09-02


[N/A][559777100] Low CVE-2026-106355: Missing authorization in Media. Reported by Google on 2026-09-10


[TBD][564085088] Low CVE-2026-106234: Use after free in Network. Reported by Findingz on 2026-09-20


[TBD][565742178] Low CVE-2026-106269: Use after free in CSS. Reported by xinyang on 2026-09-24


We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL.

Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.

Daniel Yip

Google Chrome

Extended Stable Update for Desktop

 The Extended Stable channel has been updated to 152.0.7977.158 for Windows and Mac which will roll out over the coming days/weeks.

A full list of changes in this build is available in the log. Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.

Srinivas Sista
Google Chrome

Extended Stable Update for Desktop

 The Extended Stable channel has been updated to 152.0.7977.158 for Windows and Mac which will roll out over the coming days/weeks.

A full list of changes in this build is available in the log. Interested in switching release channels? Find out how here. If you find a new issue, please let us know by filing a bug. The community help forum is also a great place to reach out for help or learn about common issues.

Srinivas Sista
Google Chrome