All incidents

Chrome 152 patches CVE-2026-79282 and over 300 other vulnerabilities

vulnerabilityopenAug 26, 2026 — Aug 26, 2026
Chrome 152 patches CVE-2026-79282 and over 300 other vulnerabilities

GOOGLE released Chrome 152 on 25 August 2026, patching CVE-2026-79282 and more than 300 additional vulnerabilities.

The flaw tracked as CVE-2026-79282 carries a CVSS score of 9.6 and is classified as critical, stemming from a use‑after‑free condition in the Aura and SafeBrowsing subsystems.

In total Chrome 152 addresses 327 security issues, ten of which are rated critical, with the majority identified through internal AI‑driven analysis; an external researcher received a $25,000 bounty for reporting CVE-2026-79282.

Google has not observed any in‑the‑wild exploitation of these flaws and no threat actors have been linked to the vulnerabilities; the update continues a trend that has seen more than 2 000 Chrome defects patched so far this year.

Defenders should ensure all endpoints are running Chrome 152 or later, preferably by enabling the browser’s automatic update mechanism and verifying version numbers after rollout.

Organisations are advised to prioritize patching of critical systems, review security logs for anomalous activity tied to the affected components, and maintain an ongoing vulnerability management programme to catch similar issues early.

Intelligence briefing updated Aug 26, 2026

CVE-2026-79282 9.6
Root sourcechromereleases.googleblog.com
Timeline Coverage

Swipe to explore timeline