Google has formally launched Chrome 151 to the Secure channel, mitigating 5 high-severity safety vulnerabilities impacting key browser engine parts, together with the V8 JavaScript engine, Blink rendering engine, Chrome Extensions framework, HTML processing layer, and TabStrip.
The replace is at the moment rolling out as model 151.0.7922.137/.138 for Home windows and macOS, whereas Linux programs obtain model 151.0.7922.137. Google famous that the replace will attain all customers worldwide over the approaching days and weeks.
Chrome 151 Patches 5 Excessive-Severity Flaws
All 5 vulnerabilities addressed in Chrome 151 belong to the use-after-free (UAF) memory security class, which happens when software program continues to entry reminiscence after it has been deallocated.
In net browsers, adversaries can try to set off these vulnerabilities utilizing maliciously crafted net scripts, HTML parts, or extension interactions.
Relying on the focused subsystem and exploit atmosphere, profitable exploitation may end up in browser crashes, delicate data disclosure, or arbitrary code execution.
Safety groups monitoring ongoing chrome security updates ought to prioritize making use of desktop browser updates throughout enterprise endpoints.
| CVE Identifier | Affected Subsystem | Severity | Reported By & Date |
| CVE-2026-19556 | V8 JavaScript Engine | Excessive | Jihyeon Jeong (Compsec Lab, SNU) — July 15, 2026 |
| CVE-2026-19557 | TabStrip Interface | Excessive | Google Inside Discovery — July 14, 2026 |
| CVE-2026-19558 | Chrome Extensions | Excessive | @bean5oup — July 20, 2026 |
| CVE-2026-19559 | HTML Processing | Excessive | Google Inside Discovery — July 28, 2026 |
| CVE-2026-19560 | Blink Rendering Engine | Excessive | WinD39 (Huynh Dinh Vu) — July 30, 2026 |
Probably the most notable vulnerability resolved on this cycle is CVE-2026-19556, a high-severity UAF flaw in V8, Chrome’s open-source JavaScript and WebAssembly engine.
Found by analysis intern Jihyeon Jeong of Compsec Lab at Seoul Nationwide College, Google awarded a $500 bug bounty for the discovering. As a result of V8 processes web-supplied JavaScript code, flaws within the V8 engine stay a main goal for browser exploits.
As highlighted within the official launch submit on the Google Chrome Releases Blog, the replace additionally fixes CVE-2026-19560 within the Blink rendering engine (reported by Huynh Dinh Vu / WinD39) and CVE-2026-19558 within the Chrome Extensions API (reported by @bean5oup).
Extension APIs and rendering engines maintain broad permissions to work together with net content material, making reminiscence security in these layers vital for stopping Chrome RCE vulnerabilities from reaching manufacturing programs.
Two further inner findings, CVE-2026-19557 within the TabStrip UI and CVE-2026-19559 in HTML parsing, exhibit that reminiscence security dangers span each front-end consumer interface parts and core net parsers.
In step with commonplace safety protocol, Google has restricted technical particulars and public proof-of-concept (PoC) data for all 5 bugs.
Particulars stay restricted till a majority of the energetic consumer base updates to Chrome 151, minimizing the danger of menace actors weaponizing patch data towards unpatched endpoints.
Google credited its safety researchers and highlighted its reliance on automated fuzzing and defensive reminiscence testing applied sciences throughout growth.
Desktop Customers: Navigate to Assist > About Google Chrome to set off the automated obtain of model 151.0.7922.137/.138 and restart the browser.
Enterprise Directors: Confirm that managed Home windows, macOS, and Linux endpoints obtain Chrome 151 via software program deployment and patch administration platforms.
[Live Webinar] Be part of Elastic & UnderDefense to find out how small safety groups can unify AI visibility and agentic response into one working mannequin -> Register Now