Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CVE-2024-23963: Apple Find My Vulnerability Exposes Real-Time User Locations
August 21, 2026
Critical TrueConf Server Flaws Let Attackers Push Malware via Updates
August 21, 2026
Critical Chrome CVE-2023-151 Allows Remote Code Execution
August 21, 2026
Home/CyberSecurity News/Critical Chrome CVE-2023-151 Allows Remote Code Execution
CyberSecurity News

Critical Chrome CVE-2023-151 Allows Remote Code Execution

Key Takeaways Google has rolled out Chrome 151 Stable, addressing seven security vulnerabilities. The most critical flaw, CVE-2026-76017, is a use-after-free bug in Chromoting, potentially enabling...

Emy Elsamnoudy
Emy Elsamnoudy
August 21, 2026 3 Min Read
3 0

Key Takeaways

  • Google has rolled out Chrome 151 Stable, addressing seven security vulnerabilities.
  • The most critical flaw, CVE-2026-76017, is a use-after-free bug in Chromoting, potentially enabling remote code execution.
  • The update is available for Windows, macOS, and Linux, with version numbers 151.0.7922.173/.174 for Windows/macOS and 151.0.7922.173 for Linux.
  • Users and administrators are urged to update Chrome immediately to mitigate the risks.

Google has recently deployed Chrome 151 Stable, an essential security update that resolves a total of seven vulnerabilities. Among these, a critical use-after-free flaw within Chromoting stands out, carrying the potential for remote code execution by malicious actors.

Table Of Content

  • Key Takeaways
  • Critical Chromoting Flaw Addressed in Chrome 151
  • What You Should Do

The updated browser version is now being distributed as 151.0.7922.173/.174 for Windows and macOS users, and 151.0.7922.173 for Linux systems. The most severe of the patched issues is identified as CVE-2026-76017, impacting Chromoting, the underlying technology powering Chrome Remote Desktop.

Google has officially categorized this vulnerability as critical. Discovered internally by Google on June 11, 2026, the flaw is a use-after-free type, a common class of memory corruption bug. These vulnerabilities arise when a program attempts to access memory that has already been deallocated and potentially reused.

Should an attacker gain reliable control over this freed memory region, they could manipulate application behavior, trigger crashes, exfiltrate sensitive data, or even inject and execute their own code on the affected system.

Critical Chromoting Flaw Addressed in Chrome 151

The fact that this critical flaw resides in Chromoting makes it particularly concerning for organizations and individuals who rely on Chrome Remote Desktop for remote access and management. Exploitation could lead to significant compromise in such environments.

Google has adopted its standard security protocol by withholding specific technical details, proof-of-concept code, and information regarding active exploitation or prerequisites. This measure is intended to minimize the window of opportunity for attackers to weaponize the vulnerability before a substantial portion of the user base has updated their browsers.

Beyond the critical Chromoting issue, Chrome 151 also addresses six high-severity vulnerabilities across various browser components. These include:

  • CVE-2026-76018: A privilege-escalation vulnerability found in the Import component, reported by Google.
  • CVE-2026-76019: An incorrect authorization flaw affecting Workers, reported anonymously.
  • CVE-2026-76020: A race condition within the V8 JavaScript engine, identified by Salvatore Gulizia (Serotav).
  • CVE-2026-76021: Another use-after-free vulnerability, this time in the Document Object Model (DOM) component, reported by Google BigSleep@Grape. DOM vulnerabilities are particularly significant as web content frequently interacts with browser rendering and scripting functions, offering potential attack vectors.
  • CVE-2026-76022: A buffer overflow issue in the Network component, credited to 0xAlessandro.
  • CVE-2026-76023: An improper resource control flaw specific to Linux Toolkit Theming, discovered by Keita Sode and Daisuke Hatakeyama of SYZD Research.

The prevalence of multiple memory-safety issues in this release highlights the ongoing importance of diligent browser patch management. Given that Chrome regularly processes untrusted web content, including JavaScript, images, and various remote resources, vulnerabilities in its core components can serve as direct conduits for attackers to compromise endpoint systems. This can occur through malicious websites, targeted advertisements, phishing links, or specially crafted web content.

Google’s commitment to security is further underscored by its acknowledgment of various security researchers and internal teams who identified these flaws during the development cycle. The Chromium project also leverages advanced security testing technologies such as AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL to proactively uncover vulnerabilities before they reach stable releases.

What You Should Do

  • Update Immediately: All users and system administrators should prioritize updating Chrome on Windows, macOS, and Linux endpoints to the latest stable version (151.0.7922.173/.174 for Windows/macOS, 151.0.7922.173 for Linux).
  • Verify Installation: Administrators should use endpoint management platforms to confirm that the updated browser version has been successfully deployed across all managed systems.
  • Restart Chrome: It is crucial to ensure that Chrome processes are restarted after the update. Simply closing the browser window may not terminate all running processes, leaving older, vulnerable versions active.
  • Manual Update Steps: Individual users can manually check for the update by opening Chrome, navigating to “Settings,” selecting “About Chrome,” and allowing the browser to download and install the latest release. Remember to restart the browser to apply the fixes.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchphishingSecurityVulnerability

Share Article

Emy Elsamnoudy

Emy Elsamnoudy

Emy is a cybersecurity analyst and reporter specializing in threat hunting, defense strategies, and industry trends. With expertise in proactive security measures, Emily covers the tools and techniques organizations use to detect and prevent cyber attacks. She is a regular speaker at security conferences and has contributed to industry reports on threat intelligence and security operations. Emily's reporting focuses on helping organizations improve their security posture through practical, actionable insights.

Previous Post

Critical Microsoft Entra ID RCE Vulnerability Exploited In The Wild

Next Post

Critical TrueConf Server Flaws Let Attackers Push Malware via Updates

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Akamai, Cloudflare CRLF Injection Flaw Exposes CDN Users to XSS
August 20, 2026
Critical Microsoft Defender Driver Vulnerability Lets Attackers Disable Security
August 20, 2026
AWS Guide: Prevent AI Agents From Accessing Unauthorized Data
August 20, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us