Google fixed 327 things in Chrome, and found 299 of them itself
Three hundred and twenty-seven. That's how many security holes Google closed in the Chrome update rolling out this week, and it isn't a typo - Chrome 152 is one of the largest single patch batches the browser has ever shipped.
Ten of them are rated critical, which in Chrome's grading means a web page could potentially do something outside the browser's protective sandbox. The one that earned the biggest reward, $25,000 to a researcher going by "Goodluck", is CVE-2026-79282, a use-after-free flaw in ANGLE, the layer Chrome uses to talk to your graphics card. Most of the rest are the same class of memory bug, spread across Chrome's interface code, its Chromecast support, its Views framework and, awkwardly, Safe Browsing. Google's advisory doesn't mention any of them being used in attacks, which is the good news here.
The detail worth pausing on is where they came from. 299 of the 327 were found by Google rather than by outside researchers, and SecurityWeek puts that down to the company's expanding use of AI to hunt bugs in its own code. That's well over two thousand Chrome flaws patched so far this year. Whatever you make of the number, the browser is being audited much harder than it used to be.
Chrome downloads updates quietly but won't finish the job until you restart it, and plenty of people never close the window. Click the three dots, then Help, then About Google Chrome - it'll fetch the update while you watch, and a Relaunch button appears when it's ready. On Windows you want 152.0.7977.64 or .65. Chrome at least nags you; the other dozen programs on your PC don't, which is what Tendvane's app-update check is for - it lists what's out of date and updates it through winget.