Chrome 152 Fixes 26 Security Flaws, Including Two Critical Bugs
Chrome 152.0.7977.75/.76 fixes 26 security vulnerabilities, including two critical use-after-free bugs in WebGL and Shared Tab Groups. Here is what the update means and why users should install it.
On this page
Google has pushed Chrome 152.0.7977.75/.76 with 26 security fixes, including two critical use-after-free vulnerabilities affecting Shared Tab Groups and WebGL. The update is already rolling out across Windows, Mac, Linux and Android, making this a routine browser update worth installing rather than postponing.Β
Chrome 152 fixes more than two dozen security problems
Google's September security release fixes 26 vulnerabilities in the Chrome browser. Two are rated critical: CVE-2026-84353, a use-after-free bug in Shared Tab Groups, and CVE-2026-84352, another use-after-free vulnerability in WebGL. Google reported both issues itself, with the Shared Tab Groups flaw reported in June and the WebGL issue reported in August. The remaining fixes include vulnerabilities rated high, medium and low, covering components such as the FileSystem, browser process, V8 JavaScript engine, graphics stack and WebRTC.Β
The dangerous part is what βuse-after-freeβ actually means
A use-after-free vulnerability happens when software continues using a piece of computer memory after that memory has already been released. If an attacker can influence what gets placed in the freed memory, the program may end up processing data that was never supposed to be there. In a browser, that matters because web pages routinely provide untrusted content that Chrome must parse and execute. Google has not published enough public detail to establish how these particular flaws could be exploited in the wild, so it would be wrong to treat either bug as a confirmed active attack. The practical lesson is simpler: a browser is exactly the kind of software where memory-safety bugs deserve prompt patching.
WebGL makes the second critical flaw especially relevant
WebGL is the browser technology that lets websites use a computer's graphics processor to render interactive 2D and 3D content. Games, visualizations, mapping tools and other graphics-heavy websites can use it without requiring a separate desktop application. The critical Chrome vulnerability in WebGL therefore sits in a part of the browser that can process content supplied by websites. Google identifies CVE-2026-84352 as a use-after-free issue and says it was reported on August 14, 2026. That does not mean simply visiting any WebGL site will compromise a computer, but it explains why the component belongs in Chrome's security update rather than being treated as an obscure internal feature.
Shared Tab Groups are another unexpected attack surface
The other critical vulnerability is in Shared Tab Groups, a Chrome feature designed to let people organize and share groups of browser tabs. Chrome has become a much larger application than a simple page viewer, and features such as tab management now contain their own complex code paths. CVE-2026-84353 is classified by Google as a critical use-after-free vulnerability in that functionality. The issue was reported by Google on June 10, well before the September patch, which also shows why a vulnerability's discovery date and public disclosure date should not be confused. Google's release notes continue to restrict some underlying bug details while users receive the fix, limiting what can responsibly be said about exploitation mechanics.Β
The update also closes flaws outside the critical pair
The two critical bugs attract the attention, but the other 24 fixes are part of the same reason to update. Google lists high-severity problems involving FileSystem authorization, information leakage in Skia, input validation in the address bar, the browser process, V8 and the graphics stack. Several medium-severity bugs affect permissions, navigation, downloads, site settings, WebRTC, media capture and tab handling. There are also lower-severity fixes involving Autofill, credentials, full-screen behavior and tab management. In other words, the release is not simply a patch for two isolated bugs; it tightens several different parts of the browser's security boundary.Β
Chrome 152.0.7977.75 is the version to look for
For desktop users, Google says Chrome 152.0.7977.75/.76 is rolling out for Windows and Mac, while Linux receives 152.0.7977.75. Chrome 152.0.7977.75 is also the Android release, and Google says Android releases contain the same security fixes as the corresponding desktop versions unless otherwise stated. The rollout is staged, so not every installation necessarily receives the update at exactly the same time. Users can check their installed version through Chrome's About page and restart the browser if an update is waiting.Β
What this means for people who use Chrome every day
For most users, there is no feature to learn and no setting to change after installing the patch. The important change is that vulnerable browser code is replaced with a fixed version before a malicious website gets an opportunity to target it. Security researchers and Google's own security systems regularly find browser flaws because modern browsers contain large amounts of code handling graphics, JavaScript, networking, files and user interface features. Google says its security bugs can be detected with tools including AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity and fuzzing systems, which automatically feed unusual inputs into software looking for crashes and memory errors.Β
The safest response is also the simplest one
Chrome's latest security release is not evidence that users are currently under attack, and Google has not said that these two critical vulnerabilities are being actively exploited. It is evidence that the browser contained 26 flaws serious enough to warrant a stable-channel update, including two bugs rated critical. Because browsers sit directly between users and content from the internet, waiting weeks to install a security update offers little practical benefit. If Chrome has not updated itself yet, checking for version 152.0.7977.75 or later is the useful next step.
Written by


