Google Chrome 148 released

The Chrome update fixes 127 vulnerabilities, including critical flaws.

Google has now released version 148 of the Chrome browser. Although version 148.0.7778.96 / 148.0.7778.97 was already made available as an "Early Stable" release for desktop on April 29, all users will now receive the new version via the browser's update function.

Version 148.0.7778.120 has been released for Google Chrome on Android. The same undisclosed security vulnerabilities were fixed here as in the desktop version.

The update addresses a total of 127 vulnerabilities, including several critical and high-severity issues affecting core browser components such as Blink, V8, ANGLE, WebRTC, GPU, and Chromoting.

Among the most serious fixes are three critical vulnerabilities

  • CVE-2026-7896 – Integer overflow in Blink
  • CVE-2026-7897 – Use-after-free vulnerability in Mobile
  • CVE-2026-7898 – Use-after-free vulnerability in Chromoting

The update also patches numerous high-severity flaws, including out-of-bounds memory access issues in V8, heap buffer overflows in ANGLE, and multiple use-after-free vulnerabilities across components such as SVG, DOM, GPU, ServiceWorker, Aura, Skia, WebRTC, and MediaRecording.

Google awarded substantial bug bounty payouts to external researchers, including rewards of $55,000 and $43,000 for several critical discoveries. Researchers from KAIST Hacking Lab, Tencent Security Xuanwu Lab, Theori, and independent security experts contributed to the findings.

Many of the vulnerabilities were identified using advanced automated security testing technologies, including:

  • AddressSanitizer
  • MemorySanitizer
  • UndefinedBehaviorSanitizer
  • Control Flow Integrity
  • libFuzzer
  • AFL

The update includes fixes across all severity levels

3 Critical vulnerabilities 30 High-severity vulnerabilities 66 Medium-severity vulnerabilities 27 Low-severity vulnerabilities

Read more here.

Users are strongly encouraged to update Chrome immediately to ensure protection against potential exploits and security risks.

about author