Summary
Google has released Chrome version 148.0.7778.167/168 across Windows, macOS, and Linux, addressing a staggering 79 security vulnerabilities — 14 of which are classified as critical. This is one of the largest single Chrome security updates in recent memory.
The critical flaws include use-after-free bugs across multiple core components, a script-injection vulnerability in the Sanitizer API, and a type confusion bug in the V8 JavaScript engine. Any of these could potentially allow remote code execution if a user visits a malicious website.
Google is urging all Chrome users to update their browsers immediately. The update is being rolled out progressively and should be available to all users within the coming days.
Sources
- Forbes — How To Fix Google Chrome’s 14 New Critical Security Vulnerabilities
- GBHackers — Google Patches 79 Chrome Security Vulnerabilities
Commentary
Fourteen critical vulnerabilities in a single Chrome release is eye-watering. V8 type confusion bugs and use-after-free flaws in core components are the bread and butter of browser exploit chains — these are the exact primitives that get chained together for full RCE in the wild.
With Chrome commanding roughly 65% of global browser market share, the blast radius of any unpatched critical flaw is enormous. The good news is Chrome’s auto-update mechanism means most users will get patched passively. But enterprise environments with managed rollouts should prioritize pushing this update immediately. If you haven’t restarted your browser in a while, now is the time.
