tlder@devChrome 149 patches 33 vulnerabilities in one drop — seven rated Critical
tlder@dev:~$
Cross-Cutting/security, web

Chrome 149 patches 33 vulnerabilities in one drop — seven rated Critical

  • Discussion

Thirty-three patches in one Chrome stable release. Seven of them are rated Critical — all use-after-free vulnerabilities spread across WebShare, WebView, Digital Credentials, File Input, Password management, and Web Authentication components. The full CVE list lands with the builds; the version to be on is 149.0.7827.155 or later on Windows/Mac, or 149.0.7827.155 on Linux. Chrome for Android got a companion roll-out to 149.0.7827.159 the same day. This isn't a zero-day situation like the V8 out-of-bounds patch from June 9, but use-after-free bugs in browser components can be exploitable, and seven Criticals in one batch earns immediate attention. Update Chrome before the week ends.