Drooid Logo
Back to story perspectives

Full Breakdown

Google Deploys Chrome 148 with Record-Size Security Patch

5/8/2026, 2:20:58 AM

Chrome 148 Security Update Released

Google released Chrome 148 to the stable channel for Windows, macOS, Linux, Android and iOS. The rollout includes version 148.0.7778.96 (Linux) and 148.0.7778.96/97 (Windows/macOS) and reaches the Extended Stable Channel for Windows/macOS. Chrome updates automatically; users may trigger a manual check via Help -> About Google Chrome.

Key Vulnerabilities Fixed

The update addresses 127 reported flaws—more than double Chrome 147’s patch count. Three critical CVEs were fixed: CVE-2026-7896 (integer overflow in Blink), CVE-2026-7897 (use-after-free in mobile code), and CVE-2026-7898 (use-after-free in Chromoting). In addition, 31 high-severity bugs (mostly use-after-free) affect V8, ANGLE, WebRTC, GPU and ServiceWorker, while 66 medium-risk and 27 low-risk issues involve out-of-bounds reads/writes and heap overflows.

Data & Statistics

Google discovered 100 of the flaws; external researchers reported the remaining 27. Bounty payouts total $138,000, including $43,000 for CVE-2026-7896 and $55,000 for CVE-2026-7899 (V8 out-of-bounds bug).

Official Statements & Responses

Google states none of the patched vulnerabilities are currently exploited in the wild and urges immediate installation. The company highlights its automatic-update system and notes Chrome 149 is slated for early June. Google also reiterates its bug-bounty program, which awarded $138,000 for the disclosed issues.

Criticism & Opposition

Some observers have raised concerns about the large number of memory-safety bugs and the fact that promised features—vertical tab arrangement and immersive reading mode—remain unavailable for many users, suggesting a gap between feature rollout and security remediation.

Conflicting Reports & Gaps

Sources differ on the exact count: one reference cites “over 100,” another lists 127, and a third mentions 120 without clarification. Additionally, while one article attributes the surge in discovered bugs to AI tools, Google’s statements deny a direct AI link, creating a discrepancy over the cause of the large patch set.

What's Next

Chrome 149, expected early June, will maintain the automatic-update cadence and may finally deliver vertical-tab and immersive-reading features. Users are advised to keep browsers current and supplement updates with reputable antivirus and VPN tools.

Verbatim Quotes

  • “Chrome automatically updates across Windows, macOS, Android, and iOS platforms, though users can manually check via Help menu for immediate protection.” — Google, Chrome product documentation
  • “The update includes three critical flaws and dozens of high-severity memory safety bugs affecting core browser components such as Blink, V8, ANGLE, WebRTC, GPU, and Chromoting.” — Google, security announcement
  • “Among the most serious issues fixed in this release is CVE-2026-7896, a critical integer overflow vulnerability in Blink, Chrome’s rendering engine.” — Google, security advisory
  • “While Google has not linked the unusually high number of vulnerabilities to AI-assisted auditing, it is notable that most of the reported flaws were discovered internally by Google rather than by external researchers.” — CyberInsider