Chrome Security Update Released to Address Code Execution Vulnerabilities
## Cybersecurity: Chrome 145 Security Update
Cybersecurity: Chrome 145 Security Update
Google has released Chrome 145 to the stable channel for Windows, Mac, and Linux systems, addressing 11 security vulnerabilities that could allow attackers to execute malicious code on affected systems.
The update, announced on Tue, Feb 10, 2026, will roll out gradually over the coming days and weeks.
The update patches several high-severity vulnerabilities that pose significant risks to users.
CVE-2026-2313: A use-after-free vulnerability in CSS. This vulnerability allows attackers to execute arbitrary code by accessing memory after it has been freed. Researchers received an $8,000 bounty for this discovery. CVE-2026-2314: A heap buffer overflow in Codecs. CVE-2026-2315: Inappropriate implementation in WebGPU.
Both vulnerabilities could enable remote code execution if exploited successfully.
The update also resolves six medium-severity vulnerabilities affecting various Chrome components, including Frames, Animation, PictureInPicture, DevTools, File input, and Ozone.
The update, announced on Tue, Feb 10, 2026, will roll out gradually over the coming days and weeks.
CVE-2026-2316: Discovered by security researcher Luan Herrera, this issue addresses insufficient policy enforcement in Frames and earned a $5,000 reward.
Two low-severity vulnerabilities (CVE-2026-2322 and CVE-2026-2323) affecting File input and Downloads were also patched, with researchers receiving $1,000 and $500 rewards respectively.
Chrome 145.0.7632.45 is now available for Linux users, while Windows and Mac users will receive versions 145.0.7632.45 or 145.0.7632.46.
The update includes numerous fixes and improvements beyond security patches, with a complete changelog available through the Chromium repository.
Google credits multiple security researchers and its internal teams for discovering these vulnerabilities.
Many bugs were identified using advanced security tools including AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL.
The company maintains restricted access to detailed bug information until most users have updated their browsers.
Users should update Chrome immediately by navigating to Settings > About Chrome , where the browser will automatically check for and install the latest version.
Given the severity of the patched vulnerabilities, particularly those enabling code execution, prompt updating is essential to maintain security.
Based on reporting by GBHackers.
