Google Chrome patches 24 vulnerabilities
Google Chrome fixed multiple use-after-free and authorization flaws that could allow arbitrary code execution; no known in-the-wild exploitation yet.
MS-ISAC issued an advisory covering multiple vulnerabilities patched in Google Chrome versions prior to 152.0.7977.75/.76 (Windows/Mac) and 152.0.7977.75 (Linux). The vulnerabilities span multiple Chrome components including WebGL, V8, GPU, Dawn, WebRTC, FileSystem, Autofill, and Downloads, with the most severe issues being use-after-free and buffer overflow flaws that could allow arbitrary code execution in the context of the logged-on user. Additional issues include information leaks, missing/incorrect authorization checks, improper input validation, and UI misrepresentation bugs.
Exploitation of the most severe vulnerabilities could allow an attacker to install programs, view/change/delete data, or create new accounts with full user rights, with impact scaled to the privilege level of the compromised user account. MS-ISAC notes there are currently no reports of these vulnerabilities being exploited in the wild, and frames the potential attack vector as drive-by compromise (T1189) via malicious or compromised web content.
Defenders are advised to apply Google's updates promptly following testing, enforce least-privilege principles, restrict administrative rights to dedicated accounts, enable anti-exploitation features (DEP, WDEG, SIP/Gatekeeper), and apply web content restrictions such as DNS filtering, URL filtering, and browser extension controls. Standard patch management and vulnerability remediation cadences (CIS Safeguards 7.1, 7.4, 7.7) are recommended alongside user security awareness training.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-085
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free