Skip to content

SecurityIndependently confirmed2 publishers3 min readPublished

Chrome 152 ships 327 fixes and ten criticals, and the restart is the only one that counts

Two of the patched bugs need nothing more than a page load, according to Malwarebytes. Chrome applies fixes on restart, so uptime is the exposure operators actually own.

The Watch · Security desk

How we use AISend a correction

What happened

  • The desktop update carries 327 security fixes, ten of them rated critical.
  • Google found 299 of the 327 flaws itself, mostly with AI tooling.
  • The advisory makes no mention of exploitation in the wild.

Why it matters

  • constraint Because the fix only lands when the process restarts, fleets with long-lived browser sessions or update-blocking extensions stay vulnerable regardless of what a patch report says.
  • decision The absence of known exploitation is the only thing making a deferred restart defensible, and it decays the moment someone works the published ANGLE fix backwards.
  • exposure V8 is shared with other Chromium-based browsers, so anything on that engine in the estate is a separate patch decision a Chrome rollout does not close.
  • precedent At this discovery rate, three-figure advisories become the routine cadence, and triage capacity rather than patch availability sets the schedule.

Chrome downloads its update quietly and applies it when the process restarts, which makes the restart the control point rather than the download. Malwarebytes names the two ways that gate fails in practice: a browser session that never ends, and an extension that breaks the update flow [9]. Neither failure looks like a missing patch from the outside. Both leave a machine running the old build while the advisory is public.

That gap matters here because of how little the two highlighted bugs ask of a victim. CVE-2026-79282 in ANGLE, the graphics translation layer, is rated critical, and according to Malwarebytes a crafted HTML page can get arbitrary code running outside the browser sandbox [5]. CVE-2026-78899 is a use-after-free in V8 with a CVSS of 8.8, and the same delivery gets code running inside the sandbox [6]. Malwarebytes flagged these two out of the hundreds specifically because a visit to a malicious site is the whole precondition [8], and it notes that out-of-sandbox execution converts that visit into code on the operating system, often with no further exploitation steps needed [7]. The V8 bug is the constrained one, though the same write-up points out that chaining bugs to escape the sandbox is normal attacker practice [17].

The provenance numbers are the part worth reading twice. SecurityWeek reports that 299 of the 327 fixes were found internally by Google [10], which leaves 28 from outside [18], or about 8.6 percent of the release [19]. The externally reported minority includes the ANGLE bug, credited to a researcher named Goodluck and paid $25,000 [11]. The highest-consequence item in the release, by Malwarebytes' description of it, came from the small share Google did not find itself.

Below the ten criticals sit 61 high-severity flaws, with the remainder medium or low [12], which works out to 256 fixes in that tail [20]. Most of the criticals are use-after-free issues in components including Angle, Aura, Chromecast, Views and SafeBrowsing [4]. Google's advisory does not mention exploitation in the wild [13], and that absence is the argument anyone who wants to defer a restart will reach for. It is also the only thing standing between a published critical and a page-load-triggered compromise, and it is not a durable property.

The build strings are 152.0.7977.64/.65 for Windows and Mac and 152.0.7977.64 for Linux [3], so any inventory check keyed to a single exact string will misread a fraction of Windows and Mac fleets as unpatched or, worse, the reverse. Google has now patched well over 2,000 Chrome vulnerabilities this year [14], with SecurityWeek attributing the surge in discovery to internal AI tooling [16]. This one release is around a sixth of that annual total [21]. Advisories of this size are the output rate of the finder, not a measure of how bad this Tuesday was.

What to watch

  • Whether Google amends the advisory with exploitation detail or respins 152 out of band for either page-load-triggerable bug.
  • Whether the externally reported share keeps shrinking next release; 28 of 327 is the ratio to track as internal AI discovery scales.
  • Whether Chromium-based browsers sharing the V8 engine ship matching builds, and how far behind Chrome they land.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence78
Adoption60
Hype gap+12
Incentives55
Confidence74
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    Google announced the release of Chrome 152 on Tuesday, with patches for more than 300 vulnerabilities.

  2. [2]

    The update includes 327 security fixes, ten of which address critical vulnerabilities.

  3. [3]

    The Chrome stable channel was updated to 152.0.7977.64/.65 for Windows and Mac, and 152.0.7977.64 for Linux.

    ReportedSupportedView cited source

Sources

2 independent publishers whose own reporting we read for this story.

  1. malwarebytes.com

    1 article · August 26, 2026

    Update Chrome before you browse again
  2. securityweek.com

    1 article · August 26, 2026

    Chrome 152 Patches Over 300 Vulnerabilities

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Loading related stories