Chrome Releases (Security Updates)
chrome-releases · A · active
https://chromereleases.googleblog.com/
Chrome / ChromeOS Stable & Beta channel releases — primary citation for Chrome 0-day fixes (added 2026-05-08). Filter for 'Stable Channel Update' posts that reference CVEs / 'in the wild'. RSS at https://feeds.feedburner.com/GoogleChromeReleases also works. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → feed https://feeds.feedburner.com/GoogleChromeReleases 5 (filter for 'Stable Channel Update' posts referencing CVEs / 'in the wild'); feed summary carries the body, or webfetch the per-post chromereleases.googleblog.com URL. AVOID: Don't burn calls fetching every Beta/Dev/iOS channel post — only Stable Channel desktop updates carry the CVE/0-day security content.. | 2026-07-05 admiralty audit: A (vendor-psirt) — Google's own Chrome release channel, primary source for Chrome fixes; feed clean. Status stays active. Filter for Stable Channel desktop posts. | 2026-08-10: DEFECT: the feed subcommand returned 0 items for S1 this run despite the source being live; listing-extraction/recipe drift, not a transport block. Needs a recipe pass — do not demote (content axis unaffected). | 2026-08-11: feed-extraction defect CONFIRMED for a second consecutive run — `fetch_source.py feed https://chromereleases.googleblog.com/feeds/posts/default` routes via jina and returns count=0, and a direct GET of the listing returns the Blogger shell with no posts in the body. Next recipe attempt should try the explicit RSS alias `.../feeds/posts/default?alt=rss` or a dated archive path such as /2026/08/. | 2026-08-13: feed https://chromereleases.googleblog.com/feeds/posts/default returned count=0 for the third consecutive run; the dated listing page https://chromereleases.googleblog.com/2026/ is fetchable directly and is the working fallback. 403/empty-feed never demotes. | 2026-08-15: feeds/posts/default still returns count=0 (fourth consecutive run); the dated archive page chromereleases.googleblog.com/<year>/ is the working recipe and was used this run.
Cited in 3 entries
Citation cadence
Citation days per ISO week (2 weeks of coverage span, total 2).
- CVE-2026-47344 et al. — TYPO3 core June release: 13 CVEs across every supported branch (10.4 ELTS → 14.3 LTS)2026-06-10
- CVE-2026-11645 — Google Chrome V8 out-of-bounds read/write exploited in the wild, added to CISA KEV2026-06-10
- CVE-2026-10881 — Google Chrome (ANGLE graphics engine): out-of-bounds read/write enabling sandbox escape (CVSS 9.6)2026-06-07