Chrome Security Update – Patch for Vulnerabilities that Enables Code Execution Attacks
Google has released Chrome version 145 to the stable channel for Windows, Mac, and Linux, addressing 11 security vulnerabilities. These updates are critical as they prevent attackers from executing malicious code on user systems.
Google has released Chrome version 145 to the stable channel for Windows, Mac, and Linux, addressing 11 security vulnerabilities. These updates are critical as they prevent attackers from executing malicious code on user systems.
The update includes several high-severity fixes, most notably CVE-2026-2313, a use-after-free vulnerability in CSS, which was discovered by researchers from HexHive and the University of St. Andrews in December 2025. This vulnerability could allow attackers to execute arbitrary code.
Google's internal security team has also patched two other high-severity vulnerabilities: CVE-2026-2314, a heap buffer overflow in Codecs, and CVE-2026-2315, an inappropriate implementation in WebGPU. All these vulnerabilities could potentially be exploited for code execution.
CVE ID Severity Vulnerability Type Component Bounty
CVE-2026-2313 High Use after free CSS $8,000
CVE-2026-2314 High Heap buffer overflow Codecs N/A
CVE-2026-2315 High Inappropriate implementation WebGPU N/A
CVE-2026-2316 Medium Insufficient policy enforcement Frames $5,000
Google has released Chrome version 145 to the stable channel for Windows, Mac, and Linux, addressing 11 security vulnerabilities.
CVE-2026-2317 Medium Inappropriate implementation Animation $2,000
CVE-2026-2318 Medium Inappropriate implementation PictureInPicture $1,000
CVE-2026-2319 Medium Race condition DevTools $1,000
CVE-2026-2320 Medium Inappropriate implementation File input TBD
CVE-2026-2321 Medium Use after free Ozone N/A
CVE-2026-2322 Low Inappropriate implementation File input $1,000
CVE-2026-2323 Low Inappropriate implementation Downloads $500
The update also addresses seven medium-severity vulnerabilities, including issues such as insufficient policy enforcement in frames and race conditions in DevTools. Additionally, inappropriate implementations across components like Animation, PictureInPicture, and File input were fixed to prevent potential security bypasses or browser manipulation.
Low-severity vulnerabilities in File input and Downloads were patched, though they pose less risk to users. Google has awarded over $18,500 in bounties to researchers who disclosed these vulnerabilities.
Users are advised to update Chrome to version 145.0.7632.45 (Linux) or 145.0.7632.45/46 (Windows/Mac) immediately. While Chrome typically updates automatically, users can manually check for updates via the settings menu under "About Chrome."
Google continues to employ advanced detection tools such as AddressSanitizer, MemorySanitizer, and libFuzzer to identify vulnerabilities during development, thereby enhancing user security.
Read the official release notes for more information.
Based on reporting by Cyber Security News.
