Google Chrome 151 Patches Five High-Severity Use-After-Free Flaws in V8, Blink, and Extensions

Google has formally launched Chrome 151 to the Secure channel, mitigating 5 high-severity safety vulnerabilities impacting key browser engine parts, together with the V8 JavaScript engine, Blink rendering engine, Chrome Extensions framework, HTML processing layer, and TabStrip.

The replace is at the moment rolling out as model 151.0.7922.137/.138 for Home windows and macOS, whereas Linux programs obtain model 151.0.7922.137. Google famous that the replace will attain all customers worldwide over the approaching days and weeks.

Chrome 151 Patches 5 Excessive-Severity Flaws

All 5 vulnerabilities addressed in Chrome 151 belong to the use-after-free (UAF) memory security class, which happens when software program continues to entry reminiscence after it has been deallocated.

In net browsers, adversaries can try to set off these vulnerabilities utilizing maliciously crafted net scripts, HTML parts, or extension interactions.

Relying on the focused subsystem and exploit atmosphere, profitable exploitation may end up in browser crashes, delicate data disclosure, or arbitrary code execution.

Safety groups monitoring ongoing chrome security updates ought to prioritize making use of desktop browser updates throughout enterprise endpoints.

CVE Identifier Affected Subsystem Severity Reported By & Date
CVE-2026-19556 V8 JavaScript Engine Excessive Jihyeon Jeong (Compsec Lab, SNU) — July 15, 2026
CVE-2026-19557 TabStrip Interface Excessive Google Inside Discovery — July 14, 2026
CVE-2026-19558 Chrome Extensions Excessive @bean5oup — July 20, 2026
CVE-2026-19559 HTML Processing Excessive Google Inside Discovery — July 28, 2026
CVE-2026-19560 Blink Rendering Engine Excessive WinD39 (Huynh Dinh Vu) — July 30, 2026

Probably the most notable vulnerability resolved on this cycle is CVE-2026-19556, a high-severity UAF flaw in V8, Chrome’s open-source JavaScript and WebAssembly engine.

Found by analysis intern Jihyeon Jeong of Compsec Lab at Seoul Nationwide College, Google awarded a $500 bug bounty for the discovering. As a result of V8 processes web-supplied JavaScript code, flaws within the V8 engine stay a main goal for browser exploits.

As highlighted within the official launch submit on the Google Chrome Releases Blog, the replace additionally fixes CVE-2026-19560 within the Blink rendering engine (reported by Huynh Dinh Vu / WinD39) and CVE-2026-19558 within the Chrome Extensions API (reported by @bean5oup).

Extension APIs and rendering engines maintain broad permissions to work together with net content material, making reminiscence security in these layers vital for stopping Chrome RCE vulnerabilities from reaching manufacturing programs.

Two further inner findings, CVE-2026-19557 within the TabStrip UI and CVE-2026-19559 in HTML parsing, exhibit that reminiscence security dangers span each front-end consumer interface parts and core net parsers.

In step with commonplace safety protocol, Google has restricted technical particulars and public proof-of-concept (PoC) data for all 5 bugs.

Particulars stay restricted till a majority of the energetic consumer base updates to Chrome 151, minimizing the danger of menace actors weaponizing patch data towards unpatched endpoints.

Google credited its safety researchers and highlighted its reliance on automated fuzzing and defensive reminiscence testing applied sciences throughout growth.

Desktop Customers: Navigate to Assist > About Google Chrome to set off the automated obtain of model 151.0.7922.137/.138 and restart the browser.

Enterprise Directors: Confirm that managed Home windows, macOS, and Linux endpoints obtain Chrome 151 via software program deployment and patch administration platforms.

[Live Webinar] Be part of Elastic & UnderDefense to find out how small safety groups can unify AI visibility and agentic response into one working mannequin -> Register Now

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *