[NEW] [high] Google Chrome: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Google Chrome to execute arbitrary code, cause a denial-of-service attack, disclose confidential information, bypass security measures, or carry out other unspecified attacks.
CSIRTS triage
- What
- An attacker can exploit multiple vulnerabilities in Google Chrome to execute arbitrary code, cause a denial-of-service attack, disclose confidential information, bypass security measures, or carry out other unspecified attacks.
- Who is affected
- Users of Google Chrome are affected.
- Urgency
- Remediation is high urgency due to the potential for severe exploitation and active attacks.
- Action
- Update Google Chrome to the latest version immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Chrome
Get an email when a new Chrome advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2454
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-164130.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 11% of all scored CVEs.
- Low exploitation riskCVE-2026-164140.09% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all scored CVEs.
- Low exploitation riskCVE-2026-164150.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all scored CVEs.
- Low exploitation riskCVE-2026-164160.09% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
- Low exploitation riskCVE-2026-164170.16% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 6% of all scored CVEs.
- Low exploitation riskCVE-2026-164180.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all scored CVEs.
- Low exploitation riskCVE-2026-164190.20% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 10% of all scored CVEs.
- Low exploitation riskCVE-2026-164200.37% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 30% of all scored CVEs.
- Low exploitation riskCVE-2026-164210.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
- Low exploitation riskCVE-2026-164220.13% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-16413 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16414 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16415 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16416 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16417 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16418 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16419 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16420 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16421 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16422 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16423 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-16424 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Microsoft Edge (July 24, 2026)cert-fr-avis
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Google Chrome (July 22, 2026)cert-fr-avis
- unknownDSA-6396-1 chromium - security updatedebian
- criticalCVE-2026-16424: Use after free in GPU in Google Chrome on Android prior to 150.0.7871.182 allowed a remote att…nvd
- highCVE-2026-16423: Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who co…nvd
- highCVE-2026-16422: Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 1…nvd
- highCVE-2026-16421: Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a re…nvd
- highCVE-2026-16420: Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker …nvd
- criticalCVE-2026-16419: Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allo…nvd
- highCVE-2026-16418: Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker…nvd
Recent advisories for Google Chrome
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Google Chrome: Multiple vulnerabilitiescert-bund · 2026-07-30
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert · 2026-07-30
- mediumCVE-2026-18019: Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a re…nvd · 2026-07-30
- mediumCVE-2026-18018: Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 all…nvd · 2026-07-30
- highCVE-2026-18017: Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to ex…nvd · 2026-07-30
- mediumCVE-2026-18016: Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.…nvd · 2026-07-30
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel (ntfs3): Vulnerability allows information disclosure2026-07-31