CERT-In Warns Chrome Users: Update Now for Critical Security Flaws
The Indian Computer Emergency Response Team (CERT-In) has issued a high-severity warning for Google Chrome desktop users regarding multiple critical vulnerabilities. These flaws could enable remote attackers to execute malicious code, steal sensitive data, and compromise systems. Users on Windows, macOS, and Linux are urged to update their browsers immediately to version 151.0.7922.137/.138 or later.
Key Highlights
- CERT-In issued a high-severity warning for Google Chrome desktop users.
- Multiple critical vulnerabilities found, risking remote attacks.
- Flaws enable remote code execution, data theft, and system compromise.
- Affects Chrome on Windows, macOS, and Linux systems (versions prior to 151.0.7922.137/.138).
- Users must update their browsers immediately to patch these vulnerabilities.
- Vulnerabilities linked to 'use-after-free' issues in Chrome components.
The Indian Computer Emergency Response Team (CERT-In), the national nodal agency for responding to computer security incidents in India, has issued a high-severity warning advising millions of Google Chrome desktop users across Windows, macOS, and Linux to immediately update their browsers. This urgent advisory, officially designated as CERT-In Vulnerability Note CIVN-2026-0410 and issued on August 14, 2026, highlights multiple critical security vulnerabilities that pose a significant risk of remote attacks.
The warning stems from the identification of several security flaws that, if exploited, could allow remote attackers to execute arbitrary code, gain unauthorized access to targeted systems, steal sensitive information, or trigger denial-of-service (DoS) conditions. These potential attacks could lead to severe consequences, including the theft of personal data such as passwords and banking details, corruption of system memory, or the disruption of critical services.
Specifically, the vulnerabilities are primarily linked to 'use-after-free' issues within various core components of the Chrome browser, including the V8 JavaScript engine, TabStrip, HTML rendering framework, Extensions system, and the Blink engine. 'Use-after-free' flaws occur when a program attempts to use memory after it has been freed, which can lead to crashes, arbitrary code execution, or information disclosure. Other reported issues include memory corruption errors.
Attackers can exploit these flaws through social engineering tactics, typically by enticing users to click on malicious links or visit specially crafted web pages. Once a user accesses such malicious content, the attacker could potentially trigger arbitrary code execution, thereby gaining unauthorized control over the affected computer.
CERT-In has specified that the warning applies to Google Chrome desktop builds prior to version 151.0.7922.137/.138 for Windows and macOS users. For Linux users, the affected versions are those prior to 151.0.7922.137. Google has already released security patches to address these vulnerabilities, and these fixes are included in the updated browser versions.
Given the severity of these vulnerabilities and the widespread use of Google Chrome, CERT-In has strongly urged all users, both individuals and organizations, to update their browsers without delay. While Chrome often updates automatically in the background, users are advised to manually check for and install the latest available version to ensure the security fixes are applied.
The process for updating Chrome is straightforward: users can open the browser, click the three-dot menu icon in the top-right corner, navigate to 'Help,' and then select 'About Google Chrome.' The browser will then automatically check for and download any available updates. After the update is downloaded, users need to click 'Relaunch' to complete the installation and activate the security patches.
This high-severity warning from CERT-In underscores the critical importance of maintaining up-to-date software, especially for web browsers, which serve as primary gateways to the internet. Regular security updates help protect against malware attacks, phishing attempts, and remote hacking threats by closing known security gaps. The warning is particularly relevant for the Indian audience, as CERT-In is India's premier cybersecurity agency under the Ministry of Electronics and Information Technology (MeitY), responsible for issuing such alerts to the Indian cyber community. However, the vulnerabilities in Google Chrome are global, impacting users worldwide. The recent ChromeOS 151 update also includes 18 security fixes, aligning with the timing of these patches.
Frequently Asked Questions
What is CERT-In's warning about for Google Chrome users?
CERT-In has issued a high-severity warning for Google Chrome desktop users about multiple critical security vulnerabilities. These flaws could allow remote attackers to execute malicious code, steal sensitive data, and compromise your computer.
Which Google Chrome versions are affected by these vulnerabilities?
The warning applies to Google Chrome desktop builds prior to version 151.0.7922.137/.138 for Windows and macOS, and versions prior to 151.0.7922.137 for Linux. Users on these older versions are at risk.
What are the risks if I don't update my Chrome browser?
If you don't update, attackers could exploit the vulnerabilities by tricking you into visiting malicious websites. This could lead to remote code execution, unauthorized access to your system, theft of sensitive information like passwords and banking details, or denial-of-service conditions.
How do I update Google Chrome to protect myself?
To update, open Google Chrome, click the three-dot menu in the top-right corner, go to 'Help,' and select 'About Google Chrome.' The browser will automatically check for and download updates. After it's done, click 'Relaunch' to apply the security patches.
Is this CERT-In warning only for users in India?
While CERT-In is India's national cybersecurity agency and the warning is particularly relevant for an Indian audience, the vulnerabilities affect Google Chrome globally across all desktop operating systems (Windows, macOS, Linux). Therefore, all Chrome users worldwide should update their browsers.