Security NEXTJuly 24, 2026🇯🇵Translated from Japanese

Google Releases Fifth Chrome Security Update in July, Addressing Four High-Severity Vulnerabilities

Google has published its fifth security update for the Chrome browser in July 2026, addressing four vulnerabilities rated as High severity.

The update was released on July 23, 2026 (local time), with new versions Chrome 150.0.7871.187 and Chrome 150.0.7871.186 for Windows and macOS, and Chrome 150.0.7871.186 for Linux.

This marks the fifth security patch in the month, following earlier updates that corrected 27 vulnerabilities on July 8, 15 on July 14, 7 on July 16, and 12 on July 21.

The four issues fixed in the latest release were reported between late May and mid-June. All received a High severity rating under Google’s four-tier scale.

One of the vulnerabilities, CVE-2026-16807, involves an out-of-bounds write in the codec component that could allow data to be written beyond allocated memory.

The remaining three are Use After Free flaws: CVE-2026-16806 in WebMCP, CVE-2026-16805 in the Blink rendering engine, and CVE-2026-16804 in input processing.

Related articles

Security NEXTVulnerabilities & Exploits

SAP Releases August 2026 Security Patch Day Advisories Including Four Critical Vulnerabilities

SAP published 28 new security advisories on August 11, 2026, aligned with the monthly Patch Tuesday schedule. Four of these received the highest severity rating of Critical. The most severe issue affects SAP Commerce Cloud Data Hub Adapter with an authorization bypass flaw rated CVSS 10.0. Two code injection vulnerabilities were disclosed in SAP Manufacturing Integration and Intelligence with CVSS scores of 9.9 and 9.1. A memory corruption vulnerability impacting SAP NetWeaver and ABAP Platform received a CVSS score of 9.8. The release also incorporates one GitHub advisory and two updates to previously published advisories.

Security NEXTVulnerabilities & Exploits

WordPress 7.0.4 Released to Patch High-Severity RCE Vulnerability CVE-2026-65640

The WordPress development team has issued version 7.0.4 to address a remote code execution vulnerability tracked as CVE-2026-65640. The flaw affects installations that use the Imagick and Ghostscript image-processing components and grants code execution to users with Author privileges or higher. An attacker can upload a specially crafted PostScript file to trigger arbitrary code execution on the server. The vulnerability received a CVSS v3.0 base score of 8.8 and is rated High severity. Administrators are urged to update immediately, either manually through the dashboard or via automatic background updates. Backported fixes for the 4.7 branch are also in preparation and will be released soon.

AntiMalwareVulnerabilities & Exploits

AI Uncovers Zoom Vulnerabilities Allowing Silent Device Takeover via Screen Sharing Annotations

Researchers at A Security identified multiple vulnerabilities in Zoom that enabled attackers to compromise participant devices during video calls without any user interaction. The flaws resided in the shared annotations protocol used for drawing and marking on shared screens. Victims only needed to join a meeting where screen sharing was active, affecting both regular participants and meeting organizers. The discovery was notable because it relied on publicly available AI models, requiring fewer than 20 prompts to locate the issues and build a working exploit prototype. The vulnerabilities impacted Zoom clients across Windows, macOS, Linux, iOS, and Android. Zoom addressed the problems through security bulletin ZSB-26015 with server-side and client patches. The research highlights how AI can dramatically accelerate vulnerability discovery compared to traditional manual analysis.

HispasecVulnerabilities & Exploits

Attackers Exploit Critical CVE-2026-59310 in VMware vCenter for Persistent Remote Access

A critical vulnerability identified as CVE-2026-59310 in Broadcom VMware vCenter Server is being actively exploited in the wild against internet-exposed instances. The flaw resides in the Syslog server component and enables remote code execution through a path traversal weakness, carrying a CVSS score of 9.8. Attackers have been observed deploying malicious cron jobs and the reverse_ssh tool to establish persistent outbound command-and-control channels since early August 2026. The campaign has impacted 361 unique IP addresses across 47 countries, with notable concentrations in Germany, the United States, Turkey, Iran, and France. Broadcom has released patches under advisory VMSA-2026-0006.1, which also addresses the related CVE-2026-59309, and strongly recommends immediate updates along with network segmentation and log reviews. No workarounds exist, making prompt patching the only effective mitigation.