$ techbeacon▋
CVE & Exploits

Google Rolls Out Chrome 152 Update Fixing 26 Flaws, Including Critical WebGL and Tab‑Group Bugs

Google Rolls Out Chrome 152 Update Fixing 26 Flaws, Including Critical WebGL and Tab‑Group Bugs

Google has issued a new stable‑channel update for its Chrome browser on desktop operating systems, moving the product to version 152.0.7977.75 and patching a total of 26 security vulnerabilities.

Among the fixes are two critical use‑after‑free bugs—one in the WebGL graphics library and another in the Shared Tab Groups feature. Use‑after‑free errors can allow malicious code to run with the same privileges as the browser, potentially giving attackers control over a user’s system.

The WebGL flaw could be triggered by specially crafted web content that manipulates graphics buffers, while the Shared Tab Groups issue pertains to the collaborative tab‑grouping tool that lets multiple users view and edit the same set of tabs. Both vulnerabilities could be exploited remotely without user interaction, a scenario that security experts consider high‑risk.

Chrome commands a dominant share of the web browser market, making timely patches essential to protect the billions of users who rely on it daily. Google follows a regular monthly release cadence, but critical bugs are often addressed in out‑of‑band updates such as this one.

The disclosure comes amid a broader trend of sophisticated browser exploits targeting rendering engines, JavaScript engines, and emerging collaboration features. Recent high‑profile incidents have demonstrated how attackers can leverage zero‑day flaws to bypass sandbox protections, prompting heightened scrutiny of browser security practices.

The update is being rolled out automatically to Windows, macOS and Linux machines that run the stable channel. Users are advised to restart Chrome after the download completes to ensure the patches are applied. Enterprise administrators can verify deployment through Chrome’s management console and may consider enforcing immediate updates for critical endpoints.

Looking ahead, Google has indicated that its security team will continue to monitor the ecosystem for emerging threats and that future releases will incorporate additional hardening measures. Security professionals recommend that organizations maintain up‑to‑date browsers, enable automatic updates where possible, and stay informed about vulnerability disclosures through official channels.

Source: GBHackers
Rakesh Meena — Rakesh tracks CVEs, zero-days, and exploit disclosures as they break, translating advisories into plain-language impact analysis. Background in vulnerability research, follows NVD and vendor bulletins closely.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related