Vulnerabilities · 75 days ago

Chrome Fleet Exposure Ends Only After Every Build Updates

Older Chrome builds stay a browser-based code-execution foothold until each Windows, macOS, and Linux install moves to the fixed release. In mixed fleets, one lagging platform build is enough to leave part of the environment exposed even if the rest is patched.

Google’s 149.0.7827.196/197 release closes 18 vulnerabilities, including four critical and 14 high. The affected versions are Chrome before 149.0.7827.196/197 on Windows and macOS, and before 149.0.7827.196 on Linux.

CVEs in this update

434 CVEs

Across Microsoft Edge (Chromium-based).

62 critical · 122 high · 242 medium · 8 low

0 in CISA KEV · 0 with EPSS above 1%

Highest severity: CVE-2026-13782 · 10.0 CRITICAL

Highest EPSS: CVE-2026-14104 · 0.52%

Showing the top 10 by KEV, EPSS, and severity.

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-07-01

Editions

Related stories