Google Chrome Emergency Security Update Patches Three High-Severity Vulnerabilities
## Google Chrome Security Update for Critical Vulnerabilities
Google Chrome Security Update for Critical Vulnerabilities
Google has issued a security update for its Chrome browser, advancing to version 145.0.7632.116/117 for Windows and macOS users, while Linux users receive version 144.0.7559.116.
This update, distributed progressively over the following days and weeks, addresses three high-severity vulnerabilities that, if left unaddressed, could pose significant risks to users.
All three identified vulnerabilities have been classified as High severity by Google, indicating substantial exploitation potential.
Two of these vulnerabilities involve out-of-bounds memory access , a common flaw type that can facilitate remote code execution or sandbox escape when paired with other exploits.
It is recommended that organizations and individual users operating Chrome on Windows or macOS verify their browser versions and apply the update when it becomes available in their region.
The first vulnerability, CVE-2026-3061, is an out-of-bounds read flaw in Chrome’s Media component, reported by security researcher Luke Francis on February 9, 2026.
All three identified vulnerabilities have been classified as High severity by Google, indicating substantial exploitation potential.
Out-of-bounds reads in media processing pipelines are particularly critical as they can be exploited using maliciously crafted media files or web content, making drive-by attacks via compromised websites feasible.
CVE-2026-3062 impacts Tint, the WebGPU shader compiler in Chrome, involving both out-of-bounds read and write conditions. Reported by researcher Cinzinga on February 11, 2026, this flaw is technically severe.
Out-of-bounds write vulnerabilities in graphics or shader processing can cause memory corruption, potentially allowing attackers to execute arbitrary code within the renderer process. As WebGPU adoption increases, vulnerabilities in components like Tint represent a growing attack surface.
The third vulnerability, CVE-2026-3063, pertains to an inappropriate implementation in Chrome DevTools, reported by M. Fauzan Wijaya on February 17, 2026.
Although typically less severe than memory corruption bugs, inappropriate implementations in developer tools can lead to cross-origin data leaks, privilege abuse, or security boundary bypasses under specific conditions.
Google has indicated that access to detailed bug reports will remain restricted until a majority of users have received the update. This practice limits exploitation risks by preventing threat actors from leveraging technical details before the patches are widely adopted.
CVE-2026-3061 : High severity, Media component, Out-of-bounds read, reported by Luke Francis. CVE-2026-3062 : High severity, Tint (WebGPU), Out-of-bounds read and write, reported by Cinzinga. CVE-2026-3063 : High severity, DevTools, Inappropriate implementation, reported by M. Fauzan Wijaya.
Users should check their Chrome version via chrome://settings/help and manually trigger updates if needed, rather than waiting for automatic deployment.
Enterprise administrators are advised to expedite this update through management platforms due to the High severity ratings. Google also acknowledges its internal security teams for providing additional fixes through continuous audits, fuzzing, and vulnerability research, complementing external bug bounty contributions.
Based on reporting by Cyber Security News.
