🚨 BOLO: Chrome Security Update: Law Firms Should Patch Before Browsing Again 🚨

lawyers keep your work secure, update your softwarE - update your google chrome browser now!

Solo practitioners and small firms should make updating Google Chrome a same-day task. Malwarebytes reports that Chrome’s current desktop update includes 327 security fixes, including 10 critical vulnerabilities, and that certain flaws can be triggered simply by visiting a malicious website. For a law practice handling confidential client communications, privileged work product, and sensitive financial data, that is a risk worth addressing immediately.

Chrome’s stable release has been updated to version 152.0.7977.64/.65 for Windows and Mac, and 152.0.7977.64 for Linux. The update addresses, among other issues, a critical flaw in ANGLE, Chrome’s graphics translation component, identified as CVE-2026-79282. Malwarebytes says a remote attacker could exploit that flaw through a crafted web page to execute arbitrary code outside Chrome’s browser sandbox.

That phrase—“outside the sandbox”—matters. Browser sandboxing is designed to contain web content so that a malicious site cannot easily reach the rest of the computer. A flaw that permits code execution beyond that boundary can give an attacker a path from a single web visit to the underlying operating system. That is precisely the sort of exposure lawyers should avoid when working in a browser alongside client portals, email, cloud document systems, court filing platforms, banking tools, and AI services. ⚖️

The update also remediates CVE-2026-78899, a use-after-free vulnerability in Chrome’s V8 JavaScript engine. It has a reported CVSS score of 8.8 out of 10. Even though successful exploitation occurs inside the browser sandbox, it should not be dismissed. Attackers frequently combine vulnerabilities in a chain, using one weakness to gain an initial foothold and another to widen access.

Why this is a legal-ethics issue!

its a team effort - remind your fellow lawyers to update their chrome browser today!

Technology hygiene is no longer separate from professional responsibility. ABA Model Rule 1.1 requires competent representation, and Comment 8 specifically calls on lawyers to keep abreast of “the benefits and risks associated with relevant technology.” A lawyer does not need to become a cybersecurity engineer. But maintaining a reasonably secure browser—the primary doorway to modern legal work—is a basic and manageable safeguard.

Model Rule 1.6(c) is equally relevant. It requires lawyers to make reasonable efforts to prevent unauthorized access to, or inadvertent disclosure of, client information. An unpatched browser can become an avoidable weak point in that effort. A compromised browser session could expose client documents, credentials, confidential messages, cloud-storage access, or data entered into web forms. 🔐

For firms, this update is also a reminder to think beyond the individual lawyer’s device. Rule 5.1 requires partners and managers to make reasonable efforts to ensure that firm-wide practices conform to professional obligations. Rule 5.3 similarly requires appropriate oversight of nonlawyer assistants. In practical terms, that means someone should own the checklist: browser updates, operating-system patches, password-manager deployment, multifactor authentication, and employee awareness.

Update Chrome now

On a Windows or Mac computer:

  1. Open Chrome.

  2. Select the three-dot More menu in the upper-right corner.

  3. Choose Settings.

  4. Select About Chrome.

  5. Allow Chrome to download any available update.

  6. Restart the browser to complete installation. 🔄

Chrome typically updates itself, but automatic updates can lag when the browser remains open for days, a restart is postponed, or an extension interferes with the update process. Malwarebytes specifically notes that manually checking can ensure the update is applied rather than merely downloaded.

This is a two-minute task with a potentially significant payoff. Before opening that unfamiliar link, reviewing a shared file, or logging into a client-facing platform, take a moment to confirm that Chrome is current. Security is not a one-time purchase or a single policy document. It is a set of small, repeatable habits that protect the practice and the people who trust it.

Bottom line: update Chrome, restart it, and encourage everyone in your firm to do the same today. ✅

Ep. #136: How Law Firms Can Actually Use AI: Practical Intake, Document, and Workflow Automation with Hamid Kohan

My next guest is Hamid Kohan, founder of LegalSoft and LawPractice.ai, and one of the most practical voices on applying AI inside real-world law firms.🧠 He joins me to break down how firms can move beyond the “we’ve done it this way for 40 years” mindset, modernize their tech stack, and start using AI today without taking on unnecessary risk.

Join Hamid and me as we discuss the following three questions and more!

  • What are the top three ways law firms can integrate AI using solutions like LegalSoft and LawPractice.ai into their intake, case management, and document workflows to improve efficiency and accuracy?

  • From your work directly with law firms, what are the top three challenges lawyers face in adopting AI, and how can they overcome them to modernize their practice?

  • Looking ahead, what are the top three emerging technologies beyond AI that attorneys should start exploring today to stay competitive in the legal industry?

In our conversation, we cover the following

  • 00:00 – Welcoming Hamid and overview of his tech-heavy environment

  • 00:30 – Why his team is 90% Mac while he stays on PC and Android

  • 01:10 – Running a pure cloud and SaaS setup with no true desktop environment

  • 02:00 – Treating devices as “Uber” to the web and why local power matters less

  • 02:30 – Hardware choices: HP PC, massive Samsung monitors, and 60+ browser tabs as a to‑do list

  • 03:30 – Working across 12 entities and using tabs to monitor departments and initiatives

  • 04:00 – Living in Google Chrome and managing resource usage for heavy browser workflows

  • 04:40 – Chrome extensions Hamid relies on: Adobe, malware protection, McAfee, offline document tools

  • 05:20 – Why he uses Chrome’s built-in password manager

  • 05:40 – Android Samsung smartphone and keeping mobile simple

  • 06:00 – Question 1: top three ways to integrate AI into intake, case management, and document workflows

  • 06:20 – How legal is “stuck in the past” and why Hamid saw law firms as a scaling opportunity

  • 07:10 – From CRMs and workflows to KPIs: the pre‑AI foundation for scaling law firms

  • 07:40 – The “sky dropped” moment when AI hit the legal industry

  • 08:10 – Vendor noise, “Me Too AI,” and why vertical, single‑purpose AI tools overwhelm firms

  • 08:50 – Why multi-solution AI platforms (like LawPractice.ai) will ultimately win

  • 09:20 – Why firms must start using AI now instead of waiting for perfection

  • 09:50 – Where lawyers should start with AI: document collection as a low‑risk entry point

  • 10:30 – Using AI to automate document requests via SMS, email, and calls

  • 11:00 – AI document summary that checks whether a client sent the correct document

  • 11:40 – Why AI collection and summaries are “risk-free” compared to AI drafting

  • 12:10 – Using AI for document chronologies and conservative workloads

  • 12:40 – Explaining LegalSoft: global virtual staffing for law firms across eight countries

  • 13:30 – How virtual legal staff can cut overhead by up to 75% for firms

  • 14:20 – Why Hamid launched LawPractice.ai to AI‑enable both law firms and LegalSoft’s 4,000 professionals

  • 15:10 – Question 2: the top three challenges lawyers face when adopting AI

  • 15:30 – Challenge 1: finding the right AI tool in a crowded, noisy market

  • 16:00 – Challenge 2: underestimating implementation, training, and real‑world usage

  • 16:20 – Case example: an employment firm that changed its view of AI after proper training

  • 17:10 – Challenge 3: signing long-term AI contracts before proper testing

  • 17:30 – Why firms should insist on “try before you buy” pilot periods

  • 18:00 – Making AI usage mandatory to avoid adoption resistance inside the firm

  • 18:40 – Parallels with CRMs like Clio, Filevine, and CasePeer and partial user adoption

  • 19:20 – How poor CRM data entry disrupts the entire legal workflow

  • 20:00 – Question 3: “beyond AI” tech and why Hamid says it’s “AI, AI, AI” for now

  • 20:30 – The real three “emerging tech” priorities: selecting, implementing, and integrating AI

  • 21:00 – Why locking into long-term tech contracts is risky in a fast-moving AI landscape

  • 21:30 – The trap of attractive multi‑year discounts and what firms should watch for

  • 22:00 – Where listeners can find Hamid and book a one‑on‑one through LegalSoft

Resources

Mentioned in the episode

  • Hardware mentioned in the conversation

  • Software & Cloud Services mentioned in the conversation