SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Vendor Security Posture Report Card: Google - Q2 2026

Vendor Security Posture Report Card: Google - Q2 2026

Google’s Chrome security posture for Q2 2026 is rated Adequate. Four milestone releases reported 1,047 security fixes, including numerous Critical vulnerabilities, while no confirmed in-the-wild exploitation notice was identified during the quarter.

Oct 9, 2026By Aditya Jha9 min read

Vendor Security Posture Report Card: Google — Q2 2026

April 1 to June 30, 2026.

Vendor Summary

FieldNotes
Vendor NameGoogle
Product Lines CoveredChrome Stable for desktop on Windows, macOS and Linux.
Reporting PeriodQ2 2026 (April 1 to June 30, 2026)
Overall Posture RatingConcerning
Prior Period RatingUnavailable; this is the earliest quarter assessed in this series.
Total CVEs Disclosed (Period)1,511 distinct CVEs listed in Chrome desktop Stable advisories (at least 1,529 security fixes).
Critical and High Severity Count682 advisory-listed CVEs: 127 Critical and 555 High, using Chromium's severity labels.
CVEs With Confirmed In-the-Wild Exploitation1 associated with a Q2 vendor advisory and fix: CVE-2026-11645. CVE-2026-5281 is excluded from this count because its advisory and fix were issued on March 31.

Rating Scale Reference

The rating scale applied consistently across every report card in this series, so that ratings remain comparable from one vendor and one period to the next:

RatingCriteria
StrongDisclosure volume and severity trend stable or improving, advisories timely and complete, no unpatched critical exposure at time of writing.
AdequatePosture broadly sound with isolated gaps, such as a delayed patch cycle or an incomplete advisory, that do not indicate a systemic pattern.
Needs ImprovementRecurring gaps across the period: repeated delayed patches, incomplete disclosures, or a rising severity trend.
ConcerningEvidence of a systemic issue: sustained critical exposure, exploitation preceding a patch, or a pattern of incomplete or delayed disclosure.

Introduction

This report assesses Google's Chrome desktop security posture for Q2 2026. The overall rating is Concerning. The decisive factor is confirmed exploitation of CVE-2026-11645 before its Stable-channel fix became available.

Scope and Methodology

The assessment covers Stable release notices issued for Chrome desktop from April 1 through June 30, including milestone and point releases. ChromeOS, Android and iOS builds, the Early Stable and Extended Stable channels, Google Cloud and Google Workspace are excluded. Counts follow Google's desktop Stable notices, which list milestone-wide Chromium CVEs. Some entries concern components for other platforms and are not filtered out. Accordingly, 1,511 is the number of distinct CVEs listed in those advisories, not the number of vulnerabilities confirmed to affect desktop Chrome. Sources are Google's linked release notices and release archive, their CVE identifiers and linked Chromium records, NVD vulnerability records, and the government exploitation catalog.

Counts use the current advisory snapshot checked on October 9, 2026. Fifteen release notices were reviewed, CVE identifiers were deduplicated across their named lists, and severity labels were counted separately from headline security-fix totals. Period attribution follows the original vendor advisory and release date, including for exploited CVEs. This is a retrospective assessment of Q2 releases, not an inventory frozen at quarter-end; a complete history of which CVEs were first visible by June 30 is unavailable.

The June 30 Chrome 150 notice currently reports 433 security fixes and lists 20 Critical CVEs. Launch-day reporting cited 382 fixes, including 15 Critical and 67 High. Google's feed records a July 1 update, but its metadata does not identify which fields changed, and an archived June 30 copy of Google's notice could not be recovered. The release table therefore shows the current advisory figures, while the launch-day figures are stated separately so later comparisons can use a consistent snapshot.

Vulnerability Disclosure Volume and Trend

The 15 Chrome desktop Stable advisories list 1,511 distinct CVEs. Fourteen notices give numeric security-fix totals summing to 1,469; the April 7 notice lists 60 CVEs but gives no numeric headline total. Together, these establish a lower bound of 1,529 security fixes associated with Q2 releases. Dates below are the original publication dates shown by Google.

Date (2026)Stable build familySecurity fixesCVEs listed in advisoryCriticalHigh
April 7147.0.7727.55/.56At least 6060214
April 15147.0.7727.101/.1023131522
April 22147.0.7727.116/.11719302
April 28147.0.7727.137/.1383030423
May 5148.0.7778.96/.97126125331
May 12148.0.7778.167/.16879781436
May 19148.0.7778.178/.179161629
May 27148.0.7778.215/.216/.21715115122123
June 2149.0.7827.53/.544294292287
June 8149.0.7827.102/.10374741755
June 11149.0.7827.114/.1152727522
June 16149.0.7827.155/.1563333726
June 23149.0.7827.196/.1971818414
June 25149.0.7827.200/.2013303
June 30150.0.7871.46/.474334332088
Total15 releasesAt least 1,5291,511127555

The April 7 CVE list includes CVE-2026-13018. The April 22 notice reports 19 security fixes but names only three CVEs; May 5 reports 126 fixes and names 125 CVEs; May 12 reports 79 fixes and names 78 CVEs. These differences account for the 18 security fixes without named CVEs or severity labels. Zeroes in the severity columns mean no CVEs with that label are named in the notice. Google's June 11 post was checked separately: it names 27 CVEs, comprising 5 Critical and 22 High, matching its headline total of 27 fixes.

Milestone security-fix volume rose from at least 60 in Chrome 147 to 126, 429 and 433 in Chrome 148, 149 and 150. Their Critical counts were 2, 3, 22 and 20. June's milestones carried substantially more severe findings than April's, but Google does not establish a single cause for the increase. Fix volume alone cannot distinguish a growing defect burden from expanded discovery and disclosure. A prior-quarter volume comparison is unavailable because no equivalent Q1 inventory has been established.

Severity Distribution Analysis

The 1,511 CVEs listed in the desktop Stable advisories have the following Chromium severity distribution. These are vendor labels, not CVSS scores.

SeverityListed CVEsShare
Critical1278.4%
High55536.7%
Medium54536.1%
Low28418.8%

The template calls for severity distribution using published CVSS scores. A complete, consistently sourced CVSS dataset was unavailable for the 1,511 advisory-listed CVEs, so this section explicitly deviates from that method and uses Chromium's published severity labels instead. For the exploited CVE, the NVD record for CVE-2026-11645 displays a contributed CVSS v3.1 score of 8.8 (High), with vector AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H; NVD's own assessment was listed as not yet provided when checked on October 9, 2026. No quarter-wide CVSS distribution is presented.

The current Chrome 150 list contains 88 High CVEs as well as 20 Critical. Across the quarter, Critical and High together account for 45.1% of the advisory-listed CVEs. Monthly Critical totals rose from 11 in April to 41 in May and 75 in June. Comparison with the prior quarter or a typical Chrome distribution is unavailable without an equivalent historical dataset.

Patch and Remediation Timeliness

A disclosure-to-patch metric is unavailable. Google's notices generally publish CVE details alongside the fixed Stable build, so they establish public disclosure and patch availability on the notice date. Their “Reported by” dates instead record when Google or an external researcher submitted or identified an issue. Those dates are not public-disclosure dates and may precede the vulnerable code's applicability to Stable; report-to-release intervals therefore are not presented as disclosure-to-patch or Stable-exposure metrics.

For example, Google's June 8 notice records CVE-2026-11645 as externally reported on April 27, but the available record does not establish when the affected code first became applicable to Stable or when exploitation began. Likewise, the 2020 and 2021 report dates attached to CVE-2026-11226 and CVE-2026-8562 do not establish multi-year Stable exposure or delayed remediation.

The April 7, May 5, June 2 and June 30 milestones were exactly 28 days apart, consistent with Google's announced four-week Chrome milestone cycle. Eleven point releases supplied additional security updates between those promotions. This regular cadence is a positive operational finding, although it did not prevent the exploited vulnerability from reaching users before a fix existed.

Exploitation and Real-World Impact

One CVE in the Q2 vendor-release cohort was confirmed exploited: CVE-2026-11645, an out-of-bounds read and write in V8. Google's June 8 advisory announced Chrome 149.0.7827.102/.103 and acknowledged an existing exploit. The release contained 74 security fixes, including 17 named Critical CVEs. The exploitation catalog added CVE-2026-11645 on June 9, with a June 23 remediation deadline for covered federal systems.

Exploitation preceded patch availability. That directly satisfies the scale's Concerning criterion. One confirmed exploited CVE represents approximately 0.07% of the 1,511 advisory-listed CVEs, but this observed fraction does not measure the probability of exploitation or diminish the impact of a browser flaw that attackers could use before a fix was available.

Quarter-boundary context: Google's March 31 advisory fixed CVE-2026-5281, a Dawn use-after-free. Its catalog addition was April 1, with an April 15 due date. It belongs to Q1 under the vendor-release-date rule and is excluded from both the Q2 CVE and exploitation totals. Its April listing remains relevant to organizations entering Q2 with outstanding browser exposure.

Advisory and Communication Quality

The release notices identify fixed builds by operating system, named CVEs, Chromium severity labels, vulnerability classes and researcher report dates. Their remediation guidance centers on the fixed version and staged rollout over subsequent days or weeks. The reviewed notices do not consistently supply workarounds or explicit browser-restart guidance. Technical issue details can remain restricted until deployment is sufficiently widespread, limiting immediate independent analysis.

Publication dates and build versions are clear. Google's metadata shows that the Chrome 150 notice was published June 30 and updated July 1, but it provides no field-by-field revision history. The available primary-source record does not establish when the current counts became visible. Numeric CVSS scores for the exploited cases are available through their separate vulnerability records rather than the release notices.

Notable Incidents This Period

CVE-2026-11645: Exploited V8 Memory Access Flaw

The June 8 fix addressed a flaw that could permit code execution within the browser sandbox through crafted web content. Its confirmed exploitation before patch availability determined the Concerning rating. The available record does not establish when exploitation began; its duration and extent remain unknown.

Historical Trend Comparison

This is a limited historical comparison based on Q1 advisories, not a comparison with a previous report card; no prior-period rating is available. Google's desktop Stable notices confirmed four exploited CVEs in Q1 2026: CVE-2026-2441 in February and CVE-2026-3910, CVE-2026-3909 and CVE-2026-5281 in March. Q2 contained one confirmed exploited CVE, CVE-2026-11645, so the known-exploitation count declined from four to one quarter over quarter. Exploitation was already occurring when the fixes shipped in both periods. A disclosure-volume comparison is not presented because an equivalent Q1 notice inventory has not been compiled using the same current-advisory method.

Risk Context for Organizations

The Concerning rating warrants closer monitoring and accelerated prioritization of exploited Chrome releases. Processing untrusted web content exposes the browser to attacks before a vendor fix may exist, while staged rollout and deferred restarts can extend exposure after release.

Google's regular update cadence gives organizations repeated opportunities to reduce that exposure. The practical residual risk depends on update coverage and activation across the deployed browser estate, including applications that share Chromium components. The rating reflects the quarter's vendor evidence; it does not establish that a particular organization was compromised.

Overall Posture Rating and Rationale

Overall Q2 rating: Concerning. As documented in Exploitation and Real-World Impact, CVE-2026-11645 was exploited before its patch was available, directly meeting that rating criterion. Although known exploitation fell from four CVEs in Q1 to one in Q2, the preceding quarter's CVE-2026-5281 provides additional context: it too was exploited before its March 31 fix, although it remains outside Q2's counts. Severity Distribution Analysis records monthly Critical totals rising from 11 to 41 to 75. Patch and Remediation Timeliness documents regular releases, but the repeated cross-quarter exploitation pattern and Q2 severity trend support the Concerning rating.

Key Takeaways

  • Google's Q2 2026 Chrome desktop posture is Concerning because CVE-2026-11645 was exploited before its June 8 fix.
  • The current versions of 15 Chrome desktop Stable advisories list 1,511 distinct CVEs and establish a lower bound of 1,529 security fixes.
  • The advisory-listed CVEs include 127 Critical, 555 High, 545 Medium and 284 Low issues under Chromium's severity labels.
  • All four Chrome milestones shipped 28 days apart, with 11 additional point releases during the quarter.
  • CVE-2026-5281 is a Q1 advisory and fix with an April 1 catalog listing; it is excluded from Q2's one-CVE exploitation count.

Conclusion

Google's Q2 2026 Chrome security posture is Concerning under this report's scale. Regular updates and useful fixed-version disclosures support remediation, while confirmed pre-patch exploitation makes continued exposure significant. Ongoing vendor and compliance monitoring should track exploitation, severity patterns and update completion. The next quarterly assessment covers Q3 2026, July 1 through September 30.

Instantly Fix Risks with Saner Patch Management

Saner patch management is a continuous, automated, and integrated software that instantly fixes risks exploited in the wild. The software supports major operating systems like Windows, Linux, and macOS, as well as 550+ third-party applications.

It also allows you to set up a safe testing area to test patches before deploying them in a primary production environment. Saner patch management additionally supports a patch rollback feature in case of patch failure or a system malfunction.

Experience the fastest and most accurate patching software here.

Featured Posts

Open Vendor Security Posture Report Card: Oracle - Q2 2026
Vendor Security Posture Report Card: Oracle - Q2 2026

CVE Research

Vendor Security Posture Report Card: Oracle - Q2 2026

Explore Oracle's Q2 2026 security posture, including disclosed vulnerabilities, critical CVEs, security updates, patch management trends, exploitation risks, and key recommendations for enterprise security teams.

Oct 9, 2026

Open Vendor Security Posture Report Card: Cisco - Q2 2026
Vendor Security Posture Report Card: Cisco - Q2 2026

CVE Research

Vendor Security Posture Report Card: Cisco - Q2 2026

Explore Cisco's security posture in Q2 2026, covering disclosed vulnerabilities, critical security risks, patch management, exploitation trends, and key recommendations for enterprise security teams.

Oct 9, 2026

Open Vendor Security Posture Report Card: Adobe - Q2 2026
Vendor Security Posture Report Card: Adobe - Q2 2026

CVE Research

Vendor Security Posture Report Card: Adobe - Q2 2026

Explore Adobe's security posture in Q2 2026, including disclosed vulnerabilities, critical security risks, patch management, exploitation trends, and key recommendations for enterprise security teams.

Oct 9, 2026

Open Critical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products
vulnerability researchCritical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products

CVE Research

Critical Atlassian Flaw Exploited Within Hours of Disclosure, Affects Multiple Products

Atlassian has disclosed CVE-2026-21589, a critical unauthenticated arbitrary file access flaw affecting Bitbucket, Confluence, Jira Software, Jira Service Management, Bamboo, Crowd, Crucible, and Fisheye Data Center products. Attackers need the exact file path; directory listing is not possible. Cloud is already patched. This article covers impact, fixed versions, and temporary mitigations.

Oct 8, 2026