Google has released Chrome 152, addressing more than 300 vulnerabilities. The update is significant not only for its volume, but also for how many of those weaknesses were uncovered inside Google—many through internal processes that leverage AI-assisted discovery.
In total, the latest patches cover 327 weaknesses. According to Google’s advisory, 299 of them were discovered internally. That makes the release an important snapshot of where browser security efforts are heading: faster finding of bugs, followed by rapid remediation.
Below is what the Chrome 152 vulnerabilities update means for users and the broader security community, including severity breakdowns and the types of issues involved.
How many Chrome 152 vulnerabilities are fixed?
The Chrome 152 update patches 327 vulnerabilities. Google reports that the majority—299—were discovered internally. The remaining portion appears to have been identified through other routes, including security research outside Google.
Google also notes that this year has seen a surge in the discovery of Chrome vulnerabilities. A key driver mentioned in the advisory is the use of AI for finding issues earlier and at a higher pace than before.
Critical, high, and other severity ratings
Not all vulnerabilities carry the same risk. In this release, ten of the patched issues are rated critical. These are the most urgent items from a security standpoint, as they have the greatest potential impact.
In addition, Google assigns 61 flaws a high severity rating. The rest are classified as medium or low, which still matter for defense-in-depth, but are typically less immediately dangerous.
It’s worth emphasizing that the severity label is not the only factor that affects real-world risk; exploitability and exposure can differ. Still, a large number of high-impact issues in a single browser release is a clear signal that updating promptly is important.
Use-after-free issues dominate the patched set
Most of the critical and higher-risk problems in Chrome 152 are related to use-after-free conditions. These types of memory safety bugs can be especially dangerous because they can lead to unpredictable behavior, including potential crashes or other security outcomes.
Google’s advisory specifically points to components where these issues were found, including:
- Angle
- Aura
- Chromecast
- Views
- SafeBrowsing
While the presence of use-after-free bugs is not unusual across large codebases, the concentration across multiple components highlights the breadth of the security work behind the update.
AI discovery is accelerating, but researchers still report major bugs
Google states that most of the vulnerabilities covered by this release were found internally, and that AI has contributed to an increased rate of discovery this year. In practice, that means the security pipeline can surface bugs sooner and at scale, then move quickly into patching and validation.
At the same time, external researchers continue to uncover high-value flaws. A researcher named Goodluck, for example, has been awarded $25,000 for a critical vulnerability tracked as CVE-2026-79282.
The advisory also mentions that several other individuals received thousands of dollars through bug bounties for security issues that were fixed as part of the latest Chrome update. That combination—internal AI-assisted discovery plus ongoing independent research—helps explain why browser security remains a dynamic, shared effort.
No mention of exploitation in the wild
One reassuring detail for defenders is that Google’s advisory does not mention in-the-wild exploitation. In other words, the release does not indicate that these patched vulnerabilities have already been actively used against real-world targets at the time of publication.
Even without evidence of active exploitation, critical and high-severity vulnerabilities remain reasons to upgrade quickly. Attackers often reverse engineer fixes and identify exploit paths after patches land, so time-to-update can still matter.
Why this release matters for security teams
For organizations that manage endpoints, browser updates should be treated as part of your regular vulnerability management process. A Chrome release with 10 critical patches and 61 high items is large enough to warrant attention even if most issues are not known to be exploited immediately.
Security teams may also use the component list—Angle, Aura, Chromecast, Views, and SafeBrowsing—as a guide for understanding where memory-safety problems have occurred. While you can’t directly map these to enterprise settings without deeper technical analysis, it can still help prioritize internal review when available.
Stay current: Chrome patches hundreds of issues
Google reports that it has patched well over 2,000 Chrome vulnerabilities to date this year. That scale underscores how frequently weaknesses are being discovered and remediated across the browser ecosystem.
With Chrome 152, users get a substantial security upgrade, and the advisory suggests that AI-assisted internal discovery continues to play a larger role in how quickly vulnerabilities are identified.
For the best protection, make sure Chrome updates are enabled and applied as soon as they are available—especially when a release includes critical-severity fixes.
Bottom line
Chrome 152 vulnerabilities updates patch 327 weaknesses, including 10 critical and 61 high severity issues. Most were discovered internally by Google, with AI playing a role in boosting discovery speed, though external researchers continue to deliver major findings as well.
With no mention of in-the-wild exploitation in the advisory, the update is still a strong reminder that timely patching is essential. If you care about browser security, updating to Chrome 152 promptly is one of the most practical steps you can take.
Source: https://www.securityweek.com/chrome-152-patches-over-300-vulnerabilities/
