Skip to content
Data Breach

Google Chrome 151 Patches 370 Security Flaws, Including Seven Critical Vulnerabilities

The Stable channel has been updated to Chrome version 151.0.7922.71.72 for Windows and macOS, and 151.0.7922.71 for Linux, with the rollout taking place over the coming days and weeks. According to Google’s security advisory, this release includes 370 distinct security fixes that address vulnerabili...

· Jul 30, 2026 · 3 min read · 👁 1 views
Google Chrome 151 Patches 370 Security Flaws, Including Seven Critical Vulnerabilities

The Stable channel has been updated to Chrome version 151.0.7922.71.72 for Windows and macOS, and 151.0.7922.71 for Linux, with the rollout taking place over the coming days and weeks.

According to Google’s security advisory, this release includes 370 distinct security fixes that address vulnerabilities in core browser components, graphics, networking, and platform-specific features.

Access to detailed bug entries is restricted until most users have updated, a standard practice intended to reduce the risk of active exploitation before patches are widely distributed.

Many of these vulnerabilities were identified internally by Google’s security teams using automated bug-finding technologies such as AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL.

151 Chrome Vulnerabilities Patches

Chrome version 151 resolves seven critical vulnerabilities, all assigned CVE-2026-17650 through CVE-2026-17656. Several of these are “use-after-free” issues found in components such as Compositing, Views, Skia, and Ozone, which can often be exploited to achieve arbitrary code execution in either the renderer or browser processes.

Other critical flaws include race conditions in the Updater and insufficient validation of untrusted input in graphics libraries such as Dawn and ANGLE.

Critical Vulnerabilities Fixed

  • CVE-2026-17650: Use-after-free in Compositing.
  • CVE-2026-17651: Insufficient validation of untrusted input in Dawn.
  • CVE-2026-17652: Use-after-free in Views.
  • CVE-2026-17653: Use-after-free in Skia.
  • CVE-2026-17654: Race condition in Updater.
  • CVE-2026-17655: Insufficient validation of untrusted input in ANGLE.
  • CVE-2026-17656: Use-after-free in Ozone.

These vulnerabilities increase the potential for sandbox escapes, privilege escalation, or data corruption when an attacker can trigger specific states in the browser via malicious web content or update processes.

In addition to the critical vulnerabilities, Chrome version 151 addresses numerous high-severity issues across V8, Navigation, QUIC, Audio, Media, WebGL, and Downloads.

Many of these issues involve use-after-free errors, out-of-bounds reads/writes, integer overflows, and type confusion scenarios that can enable remote code execution or compromise the browser’s integrity.

The update also resolves a variety of medium-severity flaws across subsystems such as ANGLE, Autofill, DevTools, Extensions, WebXR, WebView, and Passwords.

These issues range from insufficient validation of untrusted input to policy bypass and cryptographic weaknesses, which could lead to data leakage, user interface spoofing, or exploitation of browser features in targeted attacks.

Google’s advisory also highlights low-severity vulnerabilities affecting components like Enterprise features, NFC, Bluetooth, Skia, Settings, Google Lens, Picture-in-Picture, and AI-related functions.

While each of these vulnerabilities may be less impactful on its own, their combined impact underscores Chrome’s extensive attack surface and the need for continuous security hardening.

Google credits both its internal teams and external security researchers, noting that many security flaws are identified during development before reaching the Stable channel.

However, given the 370 fixes included in this single release and the multiple critical memory-corruption issues, users and enterprises are strongly encouraged to update Chrome to version 151 as soon as possible.

This update is essential for reducing exposure to potential exploitation campaigns targeting these newly disclosed vulnerabilities.

Source: CybersecurityNews.com

Follow ShomoySoft for more: Follow on Facebook

💬 Comments (0)

Login to join the discussion.

No comments yet. Be the first!

Related Articles

Recommended for you