NEWS

Google Chrome Critical Update Patches High-Severity Code

Google releases emergency security update for Chrome addressing two high-severity vulnerabilities that could allow arbitrary code execution and system crashes.

Dylan H.

News Desk

February 4, 2026
3 min read
Google Chrome Critical Update Patches High-Severity Code

Emergency Chrome Update Released

Google has released a critical security update for the Chrome Stable channel, addressing two high-severity vulnerabilities that expose users to potential arbitrary code execution (ACE) and denial-of-service (DoS) attacks.

Updated Versions

PlatformVersion
Windows144.0.7559.132/.133
macOS144.0.7559.132/.133
Linux144.0.7559.132

Vulnerability Details

Memory Corruption in V8 JavaScript Engine

The first vulnerability affects Chrome's V8 JavaScript engine, the component responsible for executing JavaScript code. Memory corruption flaws in V8 are particularly dangerous because:

  • JavaScript runs automatically when visiting websites
  • Exploitation requires only visiting a malicious page
  • Successful attacks can escape the browser sandbox

Heap Overflow in Video Processing

The second vulnerability involves a heap buffer overflow in Chrome's video processing libraries. This flaw could be triggered by:

  • Maliciously crafted video files
  • Embedded video content on websites
  • Streaming media from compromised sources

Attack Scenario

1. User visits attacker-controlled website
2. Malicious JavaScript or video content triggers vulnerability
3. Memory corruption achieved in renderer process
4. Attacker executes arbitrary code
5. Potential sandbox escape for full system access

Zero-Day Status Unknown

Google has not disclosed whether these vulnerabilities are currently being exploited in the wild. Following standard practice, bug details remain restricted until the majority of users have updated.

"Given the nature of V8 and heap overflow vulnerabilities, the risk of weaponization remains high." — Cybersecurity News


How to Update Chrome

Automatic Update

Chrome should update automatically. To verify:

  1. Click the three-dot menu (⋮)
  2. Go to Help → About Google Chrome
  3. Chrome will check for and install updates
  4. Click Relaunch to complete the update

Manual Update Check

chrome://settings/help

Verify Your Version

Ensure you're running at least:

  • 144.0.7559.132 (Windows/Linux)
  • 144.0.7559.133 (Windows/macOS alternate)

Enterprise Deployment

For enterprise environments using Chrome management:

Group Policy Update

# Force Chrome update via registry
Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Google\Update" -Name "Update{8A69D345-D564-463C-AFF1-A69D9E530F96}" -Value 1
 
# Trigger update check
& "C:\Program Files\Google\Update\GoogleUpdate.exe" /ua /installsource scheduler

Chrome Browser Cloud Management

  1. Navigate to Google Admin Console
  2. Devices → Chrome → Settings
  3. Set minimum version requirement to 144.0.7559.132

Mitigation Until Patched

If immediate patching isn't possible:

  1. Disable JavaScript for untrusted sites (breaks most websites)
  2. Use Site Isolation - Already enabled by default
  3. Enable Enhanced Protection in Chrome settings
  4. Avoid untrusted websites until update is applied

Browser Security Best Practices

Enable Enhanced Safe Browsing

Settings → Privacy and security → Security → Enhanced protection

Keep Extensions Minimal

  • Remove unused extensions
  • Only install from Chrome Web Store
  • Review extension permissions regularly

Use Separate Profiles

  • Create dedicated profiles for sensitive activities
  • Banking/financial in separate profile
  • Limit cross-site tracking

Historical Context

Chrome security updates in 2026 so far:

DateVulnerabilities FixedCritical/High
Jan 983
Jan 23125
Feb 422

Sources


  • Browser Security Hardening Guide
  • Enterprise Chrome Deployment