Chrome 148 Cuts Across Chromium’s Memory-Safety Surface
Chrome 148 is not a single-fix patch. It closes a wide set of critical memory-safety bugs across Chromium subsystems, and most of the critical issues were found by Google itself, which points to ongoing weakness in the browser’s shared attack surface.
The update resolves 79 vulnerabilities, including 14 critical issues. The highlighted flaws are CVE-2026-8509, a heap buffer overflow in WebML, and CVE-2026-8510, an integer overflow in Skia. The rest of the critical bugs span UI, FileSystem, Input, Aura, HID, Blink, Tab Groups, Downloads, DataTransfer, WebShare, ANGLE, and Payments. Google also released Firefox 150.0.3 with five high-severity fixes.
For defenders, the takeaway is that Chrome’s risk here is systemic. Patch cadence matters, but so does expecting more memory-safety bugs to keep surfacing in different Chromium components.