Google releases Chrome 148 with 127 security fixes, including three critical flaws
Google Chrome 148 was released on May 7, 2026, patching 127 security vulnerabilities, including three critical flaws, to enhance browser security.
Jason Kwon ·

Google has released Chrome 148 to the stable channel, shipping version 148.0.7778.96 for Linux and 148.0.7778.96/97 for Windows and Mac. The update patches 127 security vulnerabilities, including three rated Critical.
Three critical flaws patched Google said the three Critical issues include:
- CVE-2026-7896, an integer overflow in the Blink rendering engine, reported on March 18.
- CVE-2026-7897, a use-asourceser-free vulnerability in the Mobile component, internally reported on April 18.
- CVE-2026-7898, a use-asourceser-free vulnerability in Chromoting, internally reported on April 20.
Use-asourceser-free flaws can enable arbitrary code execution by manipulating freed memory.
Google said it awarded more than $100,000 in bug bounties for the disclosed vulnerabilities.
High-severity issues include V8 and ANGLE Beyond the Critical bugs, Chrome 148 fixes multiple High-severity issues, including CVE-2026-7899, an out-of-bounds read and write in the V8 JavaScript engine.
Google also patched additional High-severity issues affecting components including ANGLE and V8, such as heap buffer overflows, use-asourceser-free bugs, and out-of-bounds memory access, alongside a range of Medium- and Low-severity issues across other Chrome components.