In ParsePayloads of AudioSdpParser.cpp, there is a possible memory corruption due to type confusion. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Palo Alto Networks incorporated the following Chromium security fixes into our products:
https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop28.html
Chromium: CVE-2026-2441 Use after free in CSS
Accessibility. A privacy issue was addressed by removing sensitive data.
Palo Alto Networks incorporated the following Chromium security fixes into our products:
https://chromereleases.googleblog.com/2025/06/extended-stable-updates-for-desktop.html https://chromereleases.googleblog.com/2025/06/extended-stable-updates-for-desktop.html https://chromereleases.googleblog.com/2025/06/extended-stable-updates-for-desktop.htmlhttps://chromereleases.googleblog.com/2025/06/extended-stable-updates-for-desktop.html https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop.html https://chromereleases.googleblog.com/2025/05/extended-stable-updates-for-desktop.html https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop27.html https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop14.html
Additionally, a vulnerability in Prisma Browser was also addressed.
Accessibility. A logic issue was addressed with improved checks.
Chromium: CVE-2023-1531 Use after free in ANGLE
Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.