Accessibility. A privacy issue was addressed by removing sensitive data.
In ParsePayloads of AudioSdpParser.cpp, there is a possible memory corruption due to type confusion. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
Chromium: CVE-2026-2441 Use after free in CSS
Accessibility. A logic issue was addressed with improved checks.
Data race in audio in Google Chrome prior to 89.0.4389.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Palo Alto Networks incorporated the following Chromium security fixes into our products:
https://chromereleases.googleblog.com/2025/10/stable-channel-update-for-desktop28.html
Palo Alto Networks incorporated the following Chromium security fixes into our products:
https://chromereleases.googleblog.com/2025/06/extended-stable-updates-for-desktop.html https://chromereleases.googleblog.com/2025/06/extended-stable-updates-for-desktop.html https://chromereleases.googleblog.com/2025/06/extended-stable-updates-for-desktop.htmlhttps://chromereleases.googleblog.com/2025/06/extended-stable-updates-for-desktop.html https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop.html https://chromereleases.googleblog.com/2025/05/extended-stable-updates-for-desktop.html https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop27.html https://chromereleases.googleblog.com/2025/05/stable-channel-update-for-desktop14.html
Additionally, a vulnerability in Prisma Browser was also addressed.
Chromium: CVE-2023-1531 Use after free in ANGLE
The Fonts implementation in Google Chrome before 40.0.2214.91 does not initialize memory for a data structure, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors.