Google Chrome users have been advised to pay attention to browser security updates after the Indian Computer Emergency Response Team issued high severity vulnerability warnings concerning the desktop version of Chrome.
CERT In, which operates under the Ministry of Electronics and Information Technology, has identified multiple vulnerabilities that could potentially be exploited by remote attackers. According to its security advisories, successful exploitation could result in arbitrary code execution, sensitive information disclosure, security bypass or denial of service, depending on the vulnerability involved.
The warning is relevant to individuals and organisations using Google Chrome on desktop computers running Windows, macOS and Linux. CERT In has advised affected users to apply the appropriate updates provided by Google.
One of the advisories identified vulnerabilities in several Chrome components, including WebAudio, WebGL, CSS, WebGPU, Dawn, FedCM and Fonts. The security issues include heap buffer overflows, out of bounds reads, use after free vulnerabilities and integer overflow problems.
These types of vulnerabilities can create opportunities for attackers to interfere with the normal operation of a browser. In certain circumstances, an attacker may attempt to exploit a vulnerable browser by persuading a user to visit a specially crafted webpage. CERT In therefore considers the potential impact significant enough to classify the affected vulnerabilities as high risk.
Another CERT In advisory identified additional vulnerabilities involving components such as CSS, Web MIDI, WebCodecs, Dawn, WebGL, PDF, WebView, Navigation and Compositing. The advisory also listed vulnerabilities involving GPU, ANGLE and V8 components.
The security concerns demonstrate why keeping a web browser updated is an important part of basic cybersecurity. Modern browsers are regularly updated because they contain numerous components responsible for processing webpages, multimedia content, graphics, documents, scripts and other online material.
Users who continue operating an outdated browser may remain exposed to vulnerabilities that have already been addressed through security updates. Attackers can potentially take advantage of publicly known weaknesses if affected systems have not been patched.
CERT In has recommended that users apply the updates specified by the software vendor. Google regularly releases Chrome security updates to address vulnerabilities discovered by its internal security teams and external researchers.
For ordinary users, updating Chrome generally does not require advanced technical knowledge. Users can open Chrome, access the browser settings and check the About Chrome section for available updates. After an update has been downloaded, Chrome may require the browser to be relaunched before the security changes become active.
Users should also avoid relying on unofficial download websites when updating their browsers. Software should preferably be updated through Chrome's built in update mechanism or Google's official distribution channels.
The warning is particularly relevant for people who use Chrome for online banking, shopping, email, government services and other activities involving sensitive information. While the existence of a vulnerability does not mean that every user has been compromised, an outdated browser can increase the potential exposure to known security weaknesses.
Businesses and organisations should also ensure that their managed computers receive security updates in a timely manner. Systems used for handling confidential information may face greater consequences if a browser vulnerability is successfully exploited.
CERT In's March 30, 2026 advisory listed affected Chrome versions below 146.0.7680.164 or 165 for Windows and macOS and below 146.0.7680.164 for Linux. The agency classified the vulnerabilities as high severity and recommended applying the relevant vendor updates.
A subsequent advisory dated April 2, 2026 identified another group of Chrome vulnerabilities and listed affected versions below 146.0.7680.177 or 178 for Windows and macOS and below 146.0.7680.177 for Linux. That advisory also noted that an exploit for one of the listed vulnerabilities had been reported in the wild.
Because Chrome releases security fixes frequently, users should not rely only on an old version number mentioned in a security report. The safest approach is to check whether the browser currently offers an available update and install the latest stable version provided by Google.
Cybersecurity experts generally recommend combining software updates with other basic security practices. Users should avoid opening suspicious links, downloading unknown files and visiting untrusted websites. Strong passwords, multi factor authentication and regularly updated operating systems can also reduce broader security risks.
The latest CERT In warnings serve as a reminder that browsers are an important part of a computer's security environment. A browser is no longer simply a tool for viewing websites. It processes complex code, multimedia content, documents and online applications, making browser security an important consideration for both individuals and organisations.
For Chrome users, the immediate recommendation is straightforward. Check the browser's current version, install any pending security update and restart Chrome if required. Users should also continue monitoring official security advisories for future updates.
CERT In's warnings do not indicate that every Chrome user has been affected by an attack. Instead, they highlight vulnerabilities that could create security risks if left unpatched. Keeping Chrome updated is therefore one of the simplest steps users can take to reduce exposure to known browser vulnerabilities.

