Chrome Fleet Exposure Ends Only After Every Build Updates

Older Chrome builds stay a browser-based code-execution foothold until each Windows, macOS, and Linux install moves to the fixed release. In mixed fleets, one lagging platform build is enough to leave part of the environment exposed even if the rest is patched. Google’s 149.0.7827.196/197 release closes 18 vulnerabilities, including four critical and 14 high. The affected versions are Chrome before 149.0.7827.196/197 on Windows and macOS, and before 149.0.7827.196 on Linux.

Part of the PlainSec briefing for 2026-07-01

Sources