
Google has patched two critical security flaws in Chrome that could let attackers take over your computer just by visiting a website — no download required. One flaw (CVE-2026-9111) could allow full remote code execution on Linux; the other (CVE-2026-9110) could let attackers show you a convincing fake login window on Windows to steal your password. A separate unpatched flaw called 'Browser Fetch' was accidentally made public in May 2026 and its exploit code is now circulating — that fix is not included in this update. Open Chrome, click the three dots top-right, go to Settings → About Chrome, and let it update to version 148.0.7778.179 — then restart the browser. 💥 #CyberNewsLive https://malwarebytes.com/blog/bugs/2026/05/update-chrome-now-critical-bugs-could-let-attackers-run-code
Post summary
Google released patches for CVE-2026-9111 and CVE-2026-9110, while an unpatched ‘Browser Fetch’ flaw with circulating exploit code remains a concern; users are urged to update to version 148.0.7778.179.



