SecurityIndependently confirmed2 publishers3 min readPublished
Chrome 152 ships 327 fixes and ten criticals, and the restart is the only one that counts
Two of the patched bugs need nothing more than a page load, according to Malwarebytes. Chrome applies fixes on restart, so uptime is the exposure operators actually own.
The Watch · Security desk
What happened
- The desktop update carries 327 security fixes, ten of them rated critical.
- Google found 299 of the 327 flaws itself, mostly with AI tooling.
- The advisory makes no mention of exploitation in the wild.
Why it matters
- constraint Because the fix only lands when the process restarts, fleets with long-lived browser sessions or update-blocking extensions stay vulnerable regardless of what a patch report says.
- decision The absence of known exploitation is the only thing making a deferred restart defensible, and it decays the moment someone works the published ANGLE fix backwards.
- exposure V8 is shared with other Chromium-based browsers, so anything on that engine in the estate is a separate patch decision a Chrome rollout does not close.
- precedent At this discovery rate, three-figure advisories become the routine cadence, and triage capacity rather than patch availability sets the schedule.
Chrome downloads its update quietly and applies it when the process restarts, which makes the restart the control point rather than the download. Malwarebytes names the two ways that gate fails in practice: a browser session that never ends, and an extension that breaks the update flow [9]. Neither failure looks like a missing patch from the outside. Both leave a machine running the old build while the advisory is public.
That gap matters here because of how little the two highlighted bugs ask of a victim. CVE-2026-79282 in ANGLE, the graphics translation layer, is rated critical, and according to Malwarebytes a crafted HTML page can get arbitrary code running outside the browser sandbox [5]. CVE-2026-78899 is a use-after-free in V8 with a CVSS of 8.8, and the same delivery gets code running inside the sandbox [6]. Malwarebytes flagged these two out of the hundreds specifically because a visit to a malicious site is the whole precondition [8], and it notes that out-of-sandbox execution converts that visit into code on the operating system, often with no further exploitation steps needed [7]. The V8 bug is the constrained one, though the same write-up points out that chaining bugs to escape the sandbox is normal attacker practice [17].
The provenance numbers are the part worth reading twice. SecurityWeek reports that 299 of the 327 fixes were found internally by Google [10], which leaves 28 from outside [18], or about 8.6 percent of the release [19]. The externally reported minority includes the ANGLE bug, credited to a researcher named Goodluck and paid $25,000 [11]. The highest-consequence item in the release, by Malwarebytes' description of it, came from the small share Google did not find itself.
Below the ten criticals sit 61 high-severity flaws, with the remainder medium or low [12], which works out to 256 fixes in that tail [20]. Most of the criticals are use-after-free issues in components including Angle, Aura, Chromecast, Views and SafeBrowsing [4]. Google's advisory does not mention exploitation in the wild [13], and that absence is the argument anyone who wants to defer a restart will reach for. It is also the only thing standing between a published critical and a page-load-triggered compromise, and it is not a durable property.
The build strings are 152.0.7977.64/.65 for Windows and Mac and 152.0.7977.64 for Linux [3], so any inventory check keyed to a single exact string will misread a fraction of Windows and Mac fleets as unpatched or, worse, the reverse. Google has now patched well over 2,000 Chrome vulnerabilities this year [14], with SecurityWeek attributing the surge in discovery to internal AI tooling [16]. This one release is around a sixth of that annual total [21]. Advisories of this size are the output rate of the finder, not a measure of how bad this Tuesday was.
What to watch
- Whether Google amends the advisory with exploitation detail or respins 152 out of band for either page-load-triggerable bug.
- Whether the externally reported share keeps shrinking next release; 28 of 327 is the ratio to track as internal AI discovery scales.
- Whether Chromium-based browsers sharing the V8 engine ship matching builds, and how far behind Chrome they land.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence78
- Adoption60
- Hype gap+12
- Incentives55
- Confidence74
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
Google announced the release of Chrome 152 on Tuesday, with patches for more than 300 vulnerabilities.
- [2]
The update includes 327 security fixes, ten of which address critical vulnerabilities.
- [3]
The Chrome stable channel was updated to 152.0.7977.64/.65 for Windows and Mac, and 152.0.7977.64 for Linux.
- [4]
Most of the ten critical vulnerabilities are use-after-free issues in components such as Angle, Aura, Chromecast, Views and SafeBrowsing.
- [5]
CVE-2026-79282 is a critical vulnerability in ANGLE (Almost Native Graphics Layer Engine); a remote attacker could exploit it using a crafted HTML page to execute arbitrary code outside the browser sandbox.
- [6]
CVE-2026-78899 is a use-after-free vulnerability in Chrome's V8 engine with a CVSS score of 8.8 out of 10; successful exploitation could allow a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.
- [7]
Chrome vulnerabilities that enable remote code execution outside the browser sandbox can turn a visit to a malicious or compromised website into direct code execution on the underlying operating system, often without requiring additional exploitation steps.
- [8]
Malwarebytes highlighted two of the hundreds of vulnerabilities because both can be triggered by simply visiting a malicious website and could attract attackers if they go unpatched for too long.
- [9]
Chrome updates automatically, but users can lag behind if they never close the browser or if something such as an extension prevents the update; a restart is required to complete the update.
- [10]
Of the 327 weaknesses patched, 299 were discovered internally by Google.
- [11]
A researcher named Goodluck was awarded $25,000 for the critical vulnerability tracked as CVE-2026-79282.
- [12]
Sixty-one flaws were rated high severity, and the rest have medium or low severity.
- [14]
Google has patched well over 2,000 Chrome vulnerabilities to date this year.
- [15]
V8 is the part of Chrome, and of other Chromium-based browsers, that runs JavaScript.
- [16]
The majority of the patched vulnerabilities were discovered internally using AI, and the use of AI has led to a surge in the discovery of Chrome vulnerabilities this year.
- [17]
Code running inside the sandbox is constrained to the browser, which lowers impact, but attackers often chain multiple vulnerabilities to escape the sandbox, so the label does not mean the flaw is harmless.
- [18]
28 of the 327 patched flaws were reported from outside Google.
- [19]
External researchers accounted for about 8.6 percent of the fixes in this release.
- [20]
256 of the fixes were rated medium or low severity.
- [21]
This single release accounts for roughly a sixth of the Chrome vulnerabilities Google has patched this year, and no more, since the annual figure is stated as a floor.
Sources
2 independent publishers whose own reporting we read for this story.
- malwarebytes.comUpdate Chrome before you browse again
1 article · August 26, 2026
- securityweek.comChrome 152 Patches Over 300 Vulnerabilities
1 article · August 26, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Browser securityFollow
- AI-Assisted Vulnerability DiscoveryFollow
- Bug Bounty EconomicsFollow
- Vulnerability Disclosure and PatchingFollow
- Memory SafetyFollow
- Endpoint Patch OperationsFollow