Full Breakdown
Google Deploys Chrome 148 with Record-Size Security Patch
5/8/2026, 2:20:58 AM
Chrome 148 Security Update Released
Google released Chrome 148 to the stable channel for Windows, macOS, Linux, Android and iOS. The rollout includes version 148.0.7778.96 (Linux) and 148.0.7778.96/97 (Windows/macOS) and reaches the Extended Stable Channel for Windows/macOS. Chrome updates automatically; users may trigger a manual check via Help -> About Google Chrome.
Key Vulnerabilities Fixed
The update addresses 127 reported flaws—more than double Chrome 147’s patch count. Three critical CVEs were fixed: CVE-2026-7896 (integer overflow in Blink), CVE-2026-7897 (use-after-free in mobile code), and CVE-2026-7898 (use-after-free in Chromoting). In addition, 31 high-severity bugs (mostly use-after-free) affect V8, ANGLE, WebRTC, GPU and ServiceWorker, while 66 medium-risk and 27 low-risk issues involve out-of-bounds reads/writes and heap overflows.
Data & Statistics
Google discovered 100 of the flaws; external researchers reported the remaining 27. Bounty payouts total $138,000, including $43,000 for CVE-2026-7896 and $55,000 for CVE-2026-7899 (V8 out-of-bounds bug).
Official Statements & Responses
Google states none of the patched vulnerabilities are currently exploited in the wild and urges immediate installation. The company highlights its automatic-update system and notes Chrome 149 is slated for early June. Google also reiterates its bug-bounty program, which awarded $138,000 for the disclosed issues.
Criticism & Opposition
Some observers have raised concerns about the large number of memory-safety bugs and the fact that promised features—vertical tab arrangement and immersive reading mode—remain unavailable for many users, suggesting a gap between feature rollout and security remediation.
Conflicting Reports & Gaps
Sources differ on the exact count: one reference cites “over 100,” another lists 127, and a third mentions 120 without clarification. Additionally, while one article attributes the surge in discovered bugs to AI tools, Google’s statements deny a direct AI link, creating a discrepancy over the cause of the large patch set.
What's Next
Chrome 149, expected early June, will maintain the automatic-update cadence and may finally deliver vertical-tab and immersive-reading features. Users are advised to keep browsers current and supplement updates with reputable antivirus and VPN tools.
Verbatim Quotes
- “Chrome automatically updates across Windows, macOS, Android, and iOS platforms, though users can manually check via Help menu for immediate protection.” — Google, Chrome product documentation
- “The update includes three critical flaws and dozens of high-severity memory safety bugs affecting core browser components such as Blink, V8, ANGLE, WebRTC, GPU, and Chromoting.” — Google, security announcement
- “Among the most serious issues fixed in this release is CVE-2026-7896, a critical integer overflow vulnerability in Blink, Chrome’s rendering engine.” — Google, security advisory
- “While Google has not linked the unusually high number of vulnerabilities to AI-assisted auditing, it is notable that most of the reported flaws were discovered internally by Google rather than by external researchers.” — CyberInsider
