VORANT. Threat Intelligence Sign in Get the full feed

ANSSI flags mass Chrome patch in 152.0.7977

routine vulnerability technology

Google Chrome before 152.0.7977.64 (Linux/Windows) and 152.0.7977.65 (Mac) fixes several hundred vulnerabilities with impact unspecified by the vendor; ANSSI advises updating.

ANSSI (CERT-FR) issued advisory CERTFR-2026-AVI-1081 covering the Google Chrome stable channel update of 25 August 2026. Several hundred CVEs are referenced, affecting Chrome versions prior to 152.0.7977.64 on Linux and Windows and prior to 152.0.7977.65 on macOS. The bulletin classifies the risk as "non spécifié par l'éditeur" — Google has not detailed the individual impacts, which is standard practice while patch adoption catches up, and the underlying issues are typically renderer memory-safety and same-origin/sandbox bugs reachable from attacker-controlled web content.

No exploitation in the wild is claimed in the advisory, no exploit code is referenced, and no indicators are supplied. The practical exposure is drive-by: a user visiting a hostile or compromised page could trigger one of these defects, so the risk profile is broad across any estate with managed browsers, including Chromium-derived browsers that will inherit the same fixes once rebased.

Defender action is straightforward: force the Chrome update channel and verify deployed versions are at or above 152.0.7977.64 (Linux/Windows) or 152.0.7977.65 (macOS), confirm the browser has actually been relaunched to apply the patch, and track Chromium-based third-party browsers for corresponding releases. Inventory-based detection of stale Chrome versions is the most useful control here; there is nothing network- or host-signature-based to hunt on from this bulletin alone.

Mentioned in this report

Vulnerabilities CVE-2026-78891CVE-2026-78892CVE-2026-78893CVE-2026-78894CVE-2026-78895CVE-2026-78896CVE-2026-78897CVE-2026-78898CVE-2026-78899CVE-2026-78900CVE-2026-78901CVE-2026-78903CVE-2026-78904CVE-2026-78905CVE-2026-78906CVE-2026-78907CVE-2026-78908CVE-2026-78909CVE-2026-78910CVE-2026-78911CVE-2026-78912CVE-2026-78913CVE-2026-78914CVE-2026-78915CVE-2026-78934CVE-2026-78935CVE-2026-78936CVE-2026-78937CVE-2026-78938CVE-2026-78939CVE-2026-78940CVE-2026-78941CVE-2026-78942CVE-2026-78943CVE-2026-78944CVE-2026-78945CVE-2026-78946CVE-2026-78947CVE-2026-78948CVE-2026-78949

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1081

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free