Vulnerabilities

Chrome 147 Patches 60 Vulnerabilities, Including Two Critical Flaws Worth $86,000

The critical vulnerabilities affect Chrome’s WebML component and they have been reported by anonymous researchers.

Chrome security

Google announced this week the first stable version of Chrome 147, which includes patches for 60 vulnerabilities, including two that have been rated critical.

The critical vulnerabilities both impact Chrome’s WebML component, which is designed for running machine learning models directly in the browser.

The security holes, reported by anonymous researchers, have been described as a heap buffer overflow (CVE-2026-5858) and an integer overflow (CVE-2026-5859).

The reporting researchers each earned $43,000 for their findings. The significant bug bounty rewards coupled with the severity rating suggest that the vulnerabilities can be exploited for sandbox escapes and/or remote code execution. 

Of the remaining vulnerabilities fixed in Chrome, 14 have been assigned a ‘high’ severity rating. 

The flaws affect Chrome components such as WebRTC, V8, WebAudio, Media, WebML, Angle, Skia, and Blink. Nearly half of them were found internally by Google, and many have been reported by anonymous researchers.

Advertisement. Scroll to continue reading.

Only for two of them the tech giant has announced a bug bounty: $11,000 for CVE-2026-5860, and $3,000 for CVE-2026-5861. 

The remaining security holes have been assigned ‘medium’ and ‘low’ severity ratings, but at least one of the medium-severity issues appears significant.

Google has paid out a $11,000 bug bounty for CVE-2026-5874, a use-after-free bug in PrivateAI.

There is no mention of any vulnerabilities being exploited in the wild. 

In late March, Google released a Chrome update to patch 21 vulnerabilities, including a zero-day exploited in malicious attacks. 

Google also announced this week that it has rolled out new session cookie protections in Chrome to prevent account compromise via stolen authentication cookies.

Related: Chrome 146 Update Patches High-Severity Vulnerabilities

Related: Chrome 146 Update Patches Two Exploited Zero-Days

Related: Google Plans Two-Week Release Schedule for Chrome

Related Content

Vulnerabilities

The flaws, CVE-2026-105133 and CVE-2026-105134, allow attackers to bypass authentication and inject OS commands.

Vulnerabilities

The security defect, tracked as CVE-2026-107406, could lead to remote code execution or denial-of-service.

Vulnerabilities

The security defects could lead to unauthorized access, information leaks, privilege escalation, DoS attacks, and remote code execution.

Vulnerabilities

Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products.

Vulnerabilities

Critical and high-severity vulnerabilities could allow attackers to bypass authentication, execute arbitrary code, and elevate their privileges.

Government

SEC Consult has published technical details on vulnerabilities mentioned in a complaint filed by several US states.

Vulnerabilities

Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track.

Mobile & Wireless

The patches resolve a critical vulnerability in Android’s System component that could lead to privilege escalation.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version