ChromeOS Stable 152.0.7977.113 (OS 16765.41.0) Patches High-Severity VM Escape and Kernel Flaws
Google has pushed ChromeOS Stable channel update 16765.41.0 (Browser 152.0.7977.113) to most Chromebooks, bundling several third-party security fixes including two high-severity issues: a KVM VM escape (CVE-2026-64561) and a Linux kernel vulnerability (CVE-2026-53359).
Google has released a new Stable channel update for ChromeOS, bringing most Chromebooks to OS version 16765.41.0 with Browser version 152.0.7977.113. The update is primarily a security-focused release, bundling fixes for several third-party components including two high-severity vulnerabilities. Chromebook administrators and users should let the automatic update apply as soon as it reaches their device.
What's fixed in this update
This release does not list any bugs reported through the ChromeOS Vulnerability Rewards Program, but it does include a set of third-party security fixes. On the high-severity side, Google addressed CVE-2026-64561, internally referenced as "Zapscape," a KVM virtual machine escape vulnerability that could allow a guest to break out of its virtualized environment, and CVE-2026-53359, a Linux kernel-level issue. Several medium-severity fixes are also included: a KVM guest-controlled index vulnerability in kvm-cpufreq, a double-free/use-after-free cleanup issue in virtio-gpu object creation, and a fix related to the MTK V4L2 decoder referenced as "Navi." Together these patches harden the virtualization and media-decoding layers that ChromeOS relies on for features like Linux (Crostini) containers and Android app support.
Why it matters for your stack
VM escape and kernel-level vulnerabilities are among the more serious classes of bugs on ChromeOS, since the platform's security model leans heavily on sandboxing and virtualization to isolate Linux apps, Android apps, and system processes from each other. A flaw like the KVM escape addressed here could, in principle, let code running inside a guest environment affect the host system, so fixing it is a meaningful hardening step even without a known public exploit. Organizations managing fleets of Chromebooks, and anyone using Linux or Android app support on ChromeOS, benefit directly from this update.
How to update
ChromeOS updates are delivered automatically through the Stable channel and typically apply on the next restart; no manual action is required beyond allowing the device to check for and install updates, which can be done from Settings > About ChromeOS > Check for updates. Devices enrolled in the Beta or Dev channel will receive this or a related build on their own schedule. Users or administrators who encounter issues after updating can file a bug or report feedback directly through Chrome's built-in reporting tools or the ChromeOS community help forums.
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email