Google promoted Chrome 149 to the stable channel with patches for 429 vulnerabilities, a record for a single Chrome refresh. Over 100 of the defects are critical and high-severity issues, mostly use-after-free and insufficient validation flaws. The most severe bug is CVE-2026-10881 (CVSS 9.6), an out-of-bounds read and write in the ANGLE graphics engine that could allow sandbox escape and code execution. Google paid roughly $208,000 in bug bounty rewards for this release.
Tap to vote and see what everyone thinks.
Google fixes one actively exploited Android zero-day, 124 flaws
Summary by ByteBrief