Google Chrome 115 Patches 37 Vulnerabilities, 7 Critical
Key Takeaways Google has released Chrome version 151, a critical update addressing 370 security vulnerabilities. Seven of these vulnerabilities are rated critical, including multiple...
Key Takeaways
- Google has released Chrome version 151, a critical update addressing 370 security vulnerabilities.
- Seven of these vulnerabilities are rated critical, including multiple “use-after-free” flaws that could lead to arbitrary code execution.
- The update applies to Windows, macOS, and Linux, with a staggered rollout expected over the coming days and weeks.
- Users are strongly advised to update their Chrome browsers immediately to mitigate significant security risks.
Google Chrome 151 Update Patches 370 Vulnerabilities, Seven Critical
Google has initiated the rollout of Chrome version 151, pushing updates to the Stable channel for desktop users across Windows, macOS, and Linux. This significant release, identified as 151.0.7922.71.72 for Windows and macOS, and 151.0.7922.71 for Linux, introduces a substantial number of security enhancements.
Table Of Content
According to Google’s official security advisory, this update incorporates 370 distinct security fixes. These patches target a broad spectrum of vulnerabilities spanning core browser components, graphics rendering engines, networking protocols, and platform-specific functionalities.
Access to detailed information regarding these bugs remains restricted. This standard industry practice by Google aims to minimize the risk of attackers exploiting newly disclosed vulnerabilities before a majority of the user base has applied the necessary updates.
A significant portion of these vulnerabilities were discovered internally by Google’s dedicated security teams. Their efforts were augmented by advanced automated bug-finding technologies, including AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL.
Critical Vulnerabilities Addressed
The latest Chrome update remediates seven critical vulnerabilities, collectively identified by CVE IDs ranging from CVE-2026-17650 to CVE-2026-17656. A notable number of these are “use-after-free” flaws, detected in critical components such as Compositing, Views, Skia, and Ozone. These types of vulnerabilities are particularly dangerous as they frequently facilitate arbitrary code execution within either the browser or renderer processes.
Beyond “use-after-free” issues, other critical flaws resolved include race conditions within the browser’s Updater component and instances of insufficient validation of untrusted input in graphics libraries like Dawn and ANGLE.
Critical Vulnerabilities Fixed:
- CVE-2026-17650: Use-after-free in Compositing.
- CVE-2026-17651: Insufficient validation of untrusted input in Dawn.
- CVE-2026-17652: Use-after-free in Views.
- CVE-2026-17653: Use-after-free in Skia.
- CVE-2026-17654: Race condition in Updater.
- CVE-2026-17655: Insufficient validation of untrusted input in ANGLE.
- CVE-2026-17656: Use-after-free in Ozone.
Exploitation of these critical vulnerabilities could potentially lead to sandbox escapes, privilege escalation, or data corruption. This risk is particularly pronounced when an attacker can manipulate specific browser states through malicious web content or compromised update mechanisms.
High and Medium Severity Fixes
In addition to the critical patches, Chrome version 151 addresses a multitude of high-severity issues. These span various browser subsystems, including V8, Navigation, QUIC, Audio, Media, WebGL, and Downloads. Common vulnerability types among these include use-after-free errors, out-of-bounds reads/writes, integer overflows, and type confusion scenarios, all of which could enable remote code execution or undermine the browser’s integrity.
The update also resolves a range of medium-severity flaws. These affect components such as ANGLE, Autofill, DevTools, Extensions, WebXR, WebView, and Passwords. These issues encompass problems like insufficient validation of untrusted input, policy bypasses, and cryptographic weaknesses, which could potentially result in data leakage, user interface spoofing, or targeted exploitation of browser features.
Low-Severity and Cumulative Impact
Google’s advisory further details patches for low-severity vulnerabilities impacting areas like Enterprise features, NFC, Bluetooth, Skia, Settings, Google Lens, Picture-in-Picture, and AI-related functions. While individually less impactful, the sheer volume of these fixes underscores the expansive attack surface of the Chrome browser and the continuous need for robust security hardening.
Google credits both its internal security teams and external researchers for their contributions to identifying these security flaws, many of which are caught during the development phase before reaching the Stable channel. However, given the 370 fixes in this release, including multiple critical memory-corruption issues, users and enterprises are strongly urged to update Chrome to version 151 without delay. This update is crucial for minimizing exposure to potential exploitation campaigns targeting these newly disclosed vulnerabilities.
What You Should Do
- Update Immediately: Ensure your Google Chrome browser is updated to version 151.0.7922.71.72 (Windows/macOS) or 151.0.7922.71 (Linux) as soon as possible.
- Enable Automatic Updates: Verify that automatic updates are enabled in your Chrome settings to receive future patches promptly.
- Restart Browser: After updating, restart your browser to ensure all patches are fully applied.
- Monitor for Exploitation: Stay vigilant for any unusual browser behavior or security advisories regarding potential exploitation of these vulnerabilities.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.