Google Chrome just patched 108 security vulnerabilities in a single update. Earlier this year, attackers exploited multiple Chrome zero-days before fixes were available.
Those numbers can make the world's most widely used browser sound like a security minefield. But vulnerability counts alone don't tell you whether Chrome is safe. What matters more is which flaws attackers can exploit, how quickly Google patches them, whether users actually install those updates, and what other defenses stand between a malicious website and the rest of your computer.
For Chrome users, the bigger question isn't whether the browser has vulnerabilities. Every major browser does. It's how much risk remains when Chrome is fully updated and what users can do about the attack paths that patches alone don't close.
- Chrome just fixed 108 security flaws
- Attackers have exploited at least seven Chrome zero-days in 2026
- A Chrome exploit doesn't necessarily mean an attacker owns your computer
- Why does Chrome have so many security vulnerabilities?
- Chrome extensions create a different kind of security risk
- Does Chrome update automatically?
- Are Edge and other Chromium browsers affected too?
- Is Chrome safer than Firefox, Edge, or Safari?
- How to make Google Chrome safer
- So, is Google Chrome safe?
Chrome just fixed 108 security flaws
The latest reminder came with Chrome 154.
As eSecurity Planet detailed, Google released Chrome 154 with fixes for 108 security vulnerabilities, including 11 rated critical. The release included fixes for memory-corruption vulnerabilities and other weaknesses that could potentially expose users to attacks.
Google's Chrome Releases blog provides security and version information for Chrome releases, although the company sometimes restricts detailed information about vulnerabilities until a sufficient number of users have installed a patched version.
A three-digit vulnerability count sounds alarming. It is also important to understand what that number means.
Security researchers, Google's own teams and outside researchers continuously examine Chrome for weaknesses. Finding and fixing vulnerabilities before attackers can widely exploit them is part of maintaining the browser.
The more consequential distinction is between a vulnerability that has been discovered and patched and a zero-day that attackers are already exploiting.
Chrome has faced both in 2026.
Attackers have exploited at least seven Chrome zero-days in 2026
Chrome's security record this year includes vulnerabilities that were exploited before users had an opportunity to patch them.
In early September, Google patched CVE-2026-85046, which became the sixth Chrome zero-day known to have been exploited in 2026, according to eSecurity Planet's coverage of the vulnerability.
The high-severity flaw affected Chrome's V8 JavaScript and WebAssembly engine. Google acknowledged that an exploit existed in the wild, although public details were initially limited to reduce the risk to users who had not yet updated.
The count did not stop there. Days later, Google released Chrome 153 and confirmed that an exploit for CVE-2026-87491 also existed in the wild, bringing the year's known total to at least seven.
Earlier in the year, Google also addressed two Chrome zero-days under active exploitation in March.
Another actively exploited vulnerability, CVE-2026-5281, affected Chrome's WebGPU implementation and was patched in April.
The pattern matters more than any one CVE. Chrome is a valuable target because compromising a browser can give attackers an initial foothold on a device people use for email, banking, business applications, cloud services, and other sensitive activities.
A Chrome exploit doesn't necessarily mean an attacker owns your computer
One important Chrome defense is its sandbox.
Chrome separates browser processes and attempts to limit what compromised code can access outside the browser. If an attacker exploits a vulnerability in a renderer, for example, Chrome's sandbox can restrict what the attacker can do next.
That is why sophisticated attacks sometimes combine multiple vulnerabilities.
An attacker might use one flaw to compromise a browser process and another to escape the sandbox or elevate privileges on the underlying operating system. The result is an exploit chain, in which multiple weaknesses are combined to bypass separate layers of protection.
That isn't merely theoretical.
Researchers observed multiple espionage groups using a Chrome-and-Windows exploit chain during the BlueMoon campaign. eSecurity Planet outlined how attackers combined Chrome and Windows zero-days to bypass the browser's defenses and compromise targeted systems.
This layered design is an important part of answering whether Chrome is safe. A vulnerability in Chrome does not automatically provide unrestricted access to the rest of a device, but a sufficiently capable attacker may look for another vulnerability to cross that boundary.
Why does Chrome have so many security vulnerabilities?
Chrome's vulnerability numbers can look enormous, particularly when an update fixes more than 100 flaws at once.
Part of the explanation is Chrome's complexity.
A modern browser isn't simply an application for displaying websites. Chrome processes JavaScript, video, audio, graphics, PDFs, WebAssembly and a long list of web APIs while communicating with the operating system, hardware and other applications.
Each additional component can expand the browser's attack surface.
Chrome also incorporates the Chromium open-source project and numerous third-party components. Google runs vulnerability-reward programs and conducts security research intended to find weaknesses before malicious attackers do. That creates a counterintuitive situation: a large number of disclosed vulnerabilities does not, by itself, prove that Chrome is less secure than a browser reporting fewer vulnerabilities.
A better question is whether a vulnerability is actually exploitable in your environment given the security controls already in place. Teams should also determine whether attackers are actively exploiting it in the wild.
Severity still matters, but it should be considered alongside how quickly a fix is available. Browser isolation and other security boundaries can further limit the extent to which exploiting one component gives an attacker access to the broader system.
Chrome extensions create a different kind of security risk
Chrome itself isn't the only thing users install in their browsers.
Extensions can add password managers, productivity tools, ad blockers, shopping features and other functionality. Depending on the permissions users grant, an extension may also be able to read or modify data on websites, access browsing activity or interact with other browser functions.
That makes malicious or compromised extensions another attack path.
Google uses the Chrome Web Store and Chrome's Safe Browsing protections to detect and remove malicious software, but those controls don't make every extension risk-free. A legitimate extension could also change ownership or later receive a malicious update.
Users should periodically review installed extensions by entering chrome://extensions in the address bar and remove software they no longer use or recognize.
Pay particular attention to extensions that request broad permissions, such as the ability to read and modify data across websites.
For organizations, browser extension management can be an important part of endpoint security. Administrators can use Chrome Enterprise policies to control which extensions employees are allowed to install.
Does Chrome update automatically?
Chrome normally checks for updates automatically and applies available updates when users close and reopen the browser. A security fix may already be downloaded, but it won't take effect until Chrome is restarted.
Someone who leaves dozens of tabs open and rarely relaunches the browser can therefore remain on a vulnerable version longer than expected.
Users can manually check by opening Chrome and going to Settings > About Chrome. Chrome will check for available updates and display the installed version.
Google can update some Chrome security protections without releasing a new browser version. However, keeping Chrome current is still necessary to receive fixes for known vulnerabilities.
When Google flags a vulnerability as actively exploited, updating should be treated as urgent rather than something to save for later.
Are Edge and other Chromium browsers affected too?
Chrome isn't the only browser built on Chromium.
Microsoft Edge, Brave, Opera and several other browsers use Chromium as their foundation. A vulnerability in a shared Chromium component can therefore affect multiple browsers, although whether a browser is affected and when it receives a fix depends on the component, browser and version involved.
That does not mean a Chrome vulnerability automatically affects every Chromium-based browser in exactly the same way.
Browser vendors integrate Chromium into their own products and may ship security fixes on different schedules. Users should rely on the security advisories and updates provided by the maker of the browser they actually use rather than assuming a Chrome update means another Chromium browser has already received the same fix.
The shared foundation also explains why major Chromium security vulnerabilities can have an impact far beyond Chrome itself.
Is Chrome safer than Firefox, Edge, or Safari?
Raw CVE totals aren't a reliable browser scorecard.
Chrome, Firefox, Safari and Edge have different architectures, release schedules, user bases and vulnerability-disclosure processes. Chrome and Edge also share substantial Chromium code, meaning some vulnerabilities may affect both browsers rather than representing independent security issues.
Raw vulnerability counts leave out important context. Chrome’s large user base gives attackers more potential targets, while the amount of security research focused on Chromium can also lead to more flaws being found and disclosed.
That makes CVE totals a poor basis for comparing browser security. A lower number can reflect fewer disclosed vulnerabilities rather than stronger security.
When evaluating a browser, consider whether reported flaws are exploitable in your environment and whether existing security controls mitigate that risk. How quickly the vendor patches vulnerabilities that are actively exploited also provides more useful context than the annual CVE count alone.
How to make Google Chrome safer
Chrome handles much of its security automatically, but users can still reduce their exposure.
A practical Chrome security checklist includes:
- Keep Chrome updated. Check Settings > About Chrome to see if the latest version is installed.
- Restart after an update. Downloading an update isn't always enough; relaunching Chrome completes the update process.
- Remove extensions you don't need. Fewer extensions mean fewer third-party components with access to browser data.
- Review extension permissions. Be especially cautious with extensions that can read and change data across websites.
- Keep Safe Browsing enabled. Google's Safe Browsing system is designed to warn users about dangerous sites, downloads, and extensions.
- Keep the operating system patched. Browser exploits can sometimes be chained with operating-system vulnerabilities to escape Chrome's defenses.
- Don't ignore Chrome security warnings. Certificate warnings, malicious download alerts, and Safe Browsing warnings appear when the browser detects potentially dangerous content.
- Use passkeys or phishing-resistant MFA where available. Passkeys and hardware security keys can provide stronger protection against credential phishing than reusable passwords or verification codes.
- For businesses, manage browsers centrally. Organizations can use enterprise policies to enforce updates, restrict extensions, and control browser settings across managed devices.
So, is Google Chrome safe?
For most users, an up-to-date Chrome installation provides multiple layers of protection against web-based attacks, including sandboxing, site isolation, Safe Browsing and rapid security updates.
But the at least seven Chrome zero-days known to have been exploited in 2026 are a reminder that no browser can guarantee every dangerous vulnerability will be discovered before attackers find it. Extensions introduce another layer of risk. Sophisticated attackers can also combine a browser vulnerability with flaws elsewhere on a device.
That makes the version of Chrome sitting on your computer more important than Chrome's overall reputation.
Keeping Chrome updated ensures fixes for known vulnerabilities actually reach the browser. Regularly restarting Chrome helps apply those updates, while removing unnecessary extensions reduces another potential attack path. Keeping the underlying operating system patched can also limit risks outside the browser itself.
Chrome's vulnerability count alone doesn't tell you how exposed you are. How quickly security fixes reach your browser matters more, as does whether extensions or other software on the device give an attacker additional paths to exploit.
Related reading: Chrome vulnerabilities aren’t the only browser risk: see how malicious extensions reached 85,000+ installs while evading traditional endpoint defenses.





