Google fixes three Chrome code-execution vulnerabilities
No active exploitation is reported, but workstation impact turns on a familiar control: whether browser users have admin rights.
TL;DR
Google released Chrome 149.0.7827.200/201 for Windows and Mac and 149.0.7827.200 for Linux to fix CVE-2026-13281, CVE-2026-13282 and CVE-2026-13283. MS-ISAC rates the risk medium for government and business entities, with no known exploitation. State, municipal, contractor and MSP teams should apply updates after testing; admin-rights browsing can turn user-context code execution into full system control.
MS-ISAC says the three Chrome flaws allow arbitrary code execution in the context of the logged-on user, with CVE-2026-13281 tied to an integer overflow in Mojo and CVE-2026-13282 and CVE-2026-13283 tied to use-after-free bugs in Payments and AdFilter. The immediate work is ordinary patch hygiene: move Windows and Mac systems to Chrome 149.0.7827.200/201 and Linux systems to 149.0.7827.200 after testing. The advisory reports no exploitation in the wild and does not set a government-specific enforcement timeline, so the practical risk control is speed plus least privilege.
Published ·Deep Fathom