The Stable channel has been updated to 148.0.7778.167/168 for Windows/Mac and 148.0.7778.167 for Linux, which will roll out over the coming days/weeks. A full list of changes in this build is available in the LogSecurity Fixes and RewardsNote: Access to bug details and links may be kept restricted until a majority of users are updated with a fix. We will also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.This update includes 79 security fixes. Below, we highlight fixes that were contributed by external researchers. Please see the Chrome Security Page for more information. Critical CVE-2026-8509: Heap buffer overflow in WebML. Reported by c6eed09fc8b174b0f3eebedcceb1e792 on 2026-03-17 Critical CVE-2026-8510: Integer overflow in Skia. Reported by q@calif.io on 2026-04-14 Critical CVE-2026-8511: Use after free in UI. Reported by Google on 2026-03-22 Critical CVE-2026-8512: Use after free in FileSystem. Reported by Google on 2026-03-24 Critical CVE-2026-8513: Use after free in Input. Reported by Google on 2026-03-25 Critical CVE-2026-8514: Use after free in Aura. Reported by Google on 2026-03-25 Critical CVE-2026-8515: Use after free in HID. Reported by Google on 2026-03-25 Critical CVE-2026-8516: Insufficient validation of untrusted input in DataTransfer. Reported by Google on 2026-03-26 Critical CVE-2026-8517: Object lifecycle issue in WebShare. Reported by Google on 2026-03-29 Critical CVE-2026-8518: Use after free in Blink. Reported by Google on 2026-03-30 Critical CVE-2026-8519: Integer overflow in ANGLE. Reported by Google on 2026-04-01 Critical CVE-2026-8520: Race in Payments. Reported by Google on 2026-04-17 Critical CVE-2026-8521: Use after free in Tab Groups. Reported by Google on 2026-04-18 Critical CVE-2026-8522: Use after free in Downloads. Reported by Google on 2026-04-19 High CVE-2026-8523: Use after free in Mojo. Reported by Paul Seekamp / nullenc0de on 2026-02-12 High...
148.0.7778.167148.0.7778.167148.0.7778.16810.0