This Week Google Twice Released Chrome 149 Stable...

Google released Chrome 149 stable twice this week, patching 3 high-risk vulnerabilities including integer overflow and use-after-free flaws affecting

Event Description

On June 23, 2026, Google first released a Chrome browser update, but just two days later, on June 25, it again released the Chrome 149 stable update, updating Windows and Mac platforms to 149.0.7827.200 and 149.0.7827.201, while Linux and Android versions were updated to 149.0.7827.200. This update patch total 3 high-risk security vulnerabilities[8].

Combined with the previous security update, Google disclosed a total of 21 security vulnerabilities in Chrome this week[8]. Regarding severity assessment, Google classified all these vulnerabilities as high-risk, but the CVE.org website maintained by MITRE has slight differences in risk level assessment[8].

Technical Analysis

CVE-2026-13281 stems from Chrome's core cross-process communication framework Mojo, which contains an integer overflow (Integer Overflow) flaw[8]. This vulnerability has a CVSS 3.1 severity score of 8.3 and is classified as high-risk[8]. CVE.org reveals that this vulnerability allows remote attackers who have already infiltrated the shader processing process to perform sandbox escape via malicious files[8].

CVE-2026-13282 and CVE-2026-13283 are both memory use-after-free (UAF) type issues[8]. CVE-2026-13282 occurs in Chrome Android's Payments component, with a CVSS 3.1 score of 6.8, classified as medium-risk (this is MITRE/CVE.org's assessment; Google officially labels it High)[8]. This vulnerability allows local attackers to corrupt memory stacks via physical device access[8].

CVE-2026-13283 occurs in the AdFilter component, with a CVSS 3.1 score of 7.5, classified as high-risk[8]. This vulnerability enables remote attackers to execute arbitrary code by persuading users to perform specific UI gestures and then using custom HTML pages[8].

Impact Scope

This update affects all Chrome browser users, covering Windows, Mac, Linux, and Android platforms[8]. Among them, CVE-2026-13282 specifically targets Chrome Android's Payments component and may affect users performing payment operations on Android devices[8].

CVE-2026-13283 involves the AdFilter component and may affect all Chrome users browsing web pages containing ads[8]. CVE-2026-13281 involves Chrome's core Mojo framework and may affect all Chrome users, especially in shader processing scenarios[8].

If attackers successfully exploit these vulnerabilities, severe consequences such as sandbox escape, arbitrary code execution, and memory corruption may occur, leading to system control, sensitive data leakage, or service disruption[6].

Protection Recommendations

All Chrome users should immediately manually update to the latest version 149.0.7827.200 (Windows/Linux/Android) or 149.0.7827.201 (Mac)[8]. Update method: Open Chrome browser, click the "..." icon at the top-left, select "Settings," choose "About Chrome" from the left list, and the system will automatically update[3].

After updating, click the "Restart" button to complete the update[3]. Users are advised to regularly check Chrome versions to ensure they use the latest stable release[3].

For organizational users, force all endpoint devices to update Chrome to the latest version via centralized management tools[3]. Additionally, implement network security monitoring to detect potential attack attempts[6].

If using Chromium-based browsers (e.g., Microsoft Edge, Vivaldi, Brave), also update to the corresponding latest version to patch related vulnerabilities[4].

Avoid downloading and executing files from unknown sources, especially malicious files involving shader processing[8]. For Android users, pay special attention to Payments component security and avoid payment operations on untrusted websites[8].

5-Step Patch Checklist

  • Step 1: Open Chrome browser, click the "..." icon at the top-left
  • Step 2: Select "Settings," then choose "About Chrome" from the left list
  • Step 3: Wait for the system to automatically update to 149.0.7827.200 or 149.0.7827.201
  • Step 4: Click the "Restart" button to complete the update
  • Step 5: Confirm Chrome version has updated to the latest stable release

References

  • This Week Google Twice Released Chrome 149 Stable Update, Patching 3 High-Risk Vulnerabilities
  • Google Released Chrome 149 Stable Update, Patching 33 Security Issues
  • Google Chrome Multiple Vulnerabilities
  • Google Urgently Released Chrome Browser High-Risk 0-day Update
  • Chromium-Based Browsers Have 60 High-Risk Security Vulnerabilities

More cybersecurity news