Chrome Releases reports:
This update includes 41 security fixes:
- [499602793] Critical CVE-2026-19137: Use after free in WebGL.
- [524824288] Critical CVE-2026-19149: Use after free in ura.
- [532941869] Critical CVE-2026-19154: Use after free in Skia.
- [534903095] Critical CVE-2026-19157: Out of bounds write in GLE.
- [537729021] Critical CVE-2026-19170: Use after free in WebGL.
- [537838324] Critical CVE-2026-19172: Use after free in Views.
- [537390933] High CVE-2026-19169: Insufficient validation of untrusted input in Contextual Tasks.
- [536945254] High CVE-2026-19168: Inappropriate implementation in V8.
- [500097298] High CVE-2026-19138: Heap buffer overflow in CrashReporting.
- [511731805] High CVE-2026-19139: Race in CredentialProvider.
- [513044017] High CVE-2026-19140: Use after free in GPU.
- [513602949] High CVE-2026-19141: Use after free in Resources.
- [515428251] High CVE-2026-19142: Use after free in Views.
- [517772612] High CVE-2026-19143: Insufficient validation of untrusted input in WebPKs.
- [520167277] High CVE-2026-19144: Use after free in HTML.
- [521878431] High CVE-2026-19145: Use after free in Translate.
- [523713150] High CVE-2026-19146: Uninitialized Use in GPU.
- [524439798] High CVE-2026-19147: Use after free in ura.
- [524460000] High CVE-2026-19148: Out of bounds write in GPU.
- [526380803] High CVE-2026-19150: Inappropriate implementation in V8.
- [530663440] High CVE-2026-19151: Use after free in V8.
- [531165110] High CVE-2026-19152: Inappropriate implementation in avigation.
- [532939327] High CVE-2026-19153: Insufficient validation of untrusted input in Workers.
- [533053621] High CVE-2026-19155: Use after free in Payments.
- [533331920] High CVE-2026-19156: Heap buffer overflow in Base.
- [535749174] High CVE-2026-19158: Use after free in Views.
- [536067175] High CVE-2026-19159: Use after free in Views.
- [536068737] High CVE-2026-19160: Uninitialized Use in Skia.
- [536165038] High CVE-2026-19161: Uninitialized Use in Skia.
- [536271629] High CVE-2026-19162: Out of bounds write in V8.
- [536449742] High CVE-2026-19163: Use after free in Media.
- [536470854] High CVE-2026-19164: Insufficient validation of untrusted input in Codecs.
- [536512612] High CVE-2026-19165: Use after free in Extensions.
- [536584251] High CVE-2026-19166: Use after free in Web uthentication.
- [536666274] High CVE-2026-19167: Integer overflow in GPU.
- [537832446] High CVE-2026-19171: Use after free in Media.
- [538332338] High CVE-2026-19173: Out of bounds write in Skia.
- [538378084] High CVE-2026-19174: Integer overflow in V8.
- [540138836] High CVE-2026-19175: Use after free in Payments.
- [540157141] High CVE-2026-19176: Use after free in Skia.
- [540289900] High CVE-2026-19177: Insufficient validation of untrusted input in UI.