Google Chrome Security Update – 14 June 2026

Google has released an updated Chrome version 149.0.7827.114/.115 for Windows and Mac, and 149.0.7827.114 for Linux.

The addressed vulnerabilities could allow the attacker to conduct denial-of-service attacks, trigger memory corruption, gain elevated privileges, obtain sensitive information, bypass security restrictions, or execute arbitrary code on the affected system via a crafted HTML page.

Sample of the addressed vulnerabilities:

1. Google Chrome Headless Insufficient Policy Enforcement Vulnerability (CVE- 2026-12027):

  • CVSS: 9.6
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Bypass Security

2. Google Chrome Core Use-After Free Vulnerability (CVE-2026-12007):

  • CVSS: 8.8
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Consequences: Remote Code Execution
Vulnerabilities
Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Google Chrome Security Update

References