Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Chrome 145 Patches 11 Vulnerabilities

Three of the security defects are high-severity flaws, two of which were found and reported by Google.

Chrome security

Google on Tuesday announced the release of Chrome 145 to the stable channel with fixes for 11 vulnerabilities, including three high-severity bugs.

First in line is CVE-2026-2313, a high-severity use-after-free issue in CSS that earned the reporting researchers an $8,000 bug bounty reward.

The two other high-severity defects, tracked as CVE-2026-2314 and CVE-2026-2315, were found and reported by Google and are described as a heap buffer overflow in Codecs and an inappropriate implementation in WebGPU, respectively.

Based on the paid bug bounty, the most serious of the medium-severity vulnerabilities patched in Chrome 145 is CVE-2026-2316, an insufficient policy enforcement issue in Frames that earned the reporting researcher $5,000.

Next in line is CVE-2026-2317, an inappropriate implementation in Animation for which Google paid a $2,000 reward.

The fresh browser update also resolves two medium-severity inappropriate implementation flaws in PictureInPicture and File input. Google says it paid $1,000 for the first, but has yet to disclose the amount for the second.

Advertisement. Scroll to continue reading.

The remaining two medium-severity issues include a race condition in DevTools and a use-after-free defect in Ozone.

Two low-severity inappropriate implementation bugs impacting File Input and Downloads were also addressed.

Overall, Google handed out over $18,000 in bug bounty rewards to the reporting researchers.

The latest Chrome iteration is now rolling out as version 145.0.7632.45 for Linux and as versions 145.0.7632.45/46 for Windows and macOS.

Google makes no mention of any of the addressed vulnerabilities being exploited in the wild. Users are advised to apply the patches as soon as possible.

Related: Chrome, Edge Extensions Caught Stealing ChatGPT Sessions

Related: Chrome 144, Firefox 147 Patch High-Severity Vulnerabilities

Related: Apple Patches iOS Zero-Day Exploited in ‘Extremely Sophisticated Attack’

Related: Ivanti Patches Endpoint Manager Vulnerabilities Disclosed in October 2025

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

People on the Move

Tim Byrd has been appointed Chief Information Security Officer at First Citizens Bank.

IRONSCALES has named Steve McKenzie as Chief Operating Officer.

Silvio Pappalardo has joined AuthMind as Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.