Google has launched a brand new Chrome Steady channel replace that fixes two critical security vulnerabilities affecting graphics-related elements. Customers ought to replace their browsers as quickly as the discharge turns into obtainable for his or her gadget.
The replace strikes Chrome to model 151.0.7922.169/.170 on Home windows and macOS, whereas Linux customers obtain model 151.0.7922.169. Google stated the rollout will happen step by step over the approaching days and weeks.
The 2 vital points are tracked as CVE-2026-76034 and CVE-2026-76036. Each are buffer overflow vulnerabilities, a memory-safety flaw that may happen when software program writes extra information right into a reminiscence space than it was designed to carry.
Such bugs can result in browser crashes, information corruption, or probably arbitrary code execution in sure assault situations. CVE-2026-76034 impacts WebGL, Chrome’s interface for rendering interactive 2D and 3D graphics inside web sites.
On-line video games, visualizations, browser-based design instruments, and different graphics-heavy net purposes extensively use WebGL. A malicious web site may probably try and set off the flaw by way of specifically crafted WebGL content material.
The second difficulty, CVE-2026-76036, is a buffer overflow in Dawn. Daybreak is Chromium’s implementation of the WebGPU normal, a more recent graphics API supposed to supply net purposes with extra direct and environment friendly entry to graphics {hardware}.
As a result of WebGPU and associated graphics elements course of complicated information from net content material, reminiscence corruption points in these areas can signify a major browser safety danger.
Google credited its personal safety staff with reporting CVE-2026-76034 on July 15, 2026, and CVE-2026-76036 on July 28, 2026. The corporate has not publicly disclosed technical particulars, proof-of-concept code, or exploitation info.
It stated entry to bug reviews might stay restricted till most Chrome customers have put in the fixes, lowering the chance for attackers to reverse-engineer patches and weaponize the vulnerabilities.
In complete, the Chrome 151 Stable release includes 15 security fixes. Google additionally famous that it makes use of memory-error detection and fuzzing applied sciences, together with AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Management Move Integrity, libFuzzer, and AFL, to establish safety bugs throughout improvement.
| CVE ID | Severity | Vulnerability sort | Affected element | Reporter | Subject ID |
|---|---|---|---|---|---|
| CVE-2026-76034 | Essential | Buffer overflow | WebGL | 534923522 | |
| CVE-2026-76036 | Essential | Buffer overflow | Daybreak | 540087398 | |
| CVE-2026-76033 | Excessive | Inappropriate implementation | CORS | 516715010 | |
| CVE-2026-76037 | Excessive | Hyperlink following | CredentialProvider | 517612295 | |
| CVE-2026-76044 | Excessive | Race situation | USB | 522732244 | |
| CVE-2026-76039 | Excessive | Incorrect reference decision | Core | 525167753 | |
| CVE-2026-76040 | Excessive | Use-after-free | Browser | 534862220 | |
| CVE-2026-76035 | Excessive | Inappropriate implementation | Media | 536439844 | |
| CVE-2026-76042 | Excessive | Use of uninitialized useful resource | GPU | 536460270 | |
| CVE-2026-76046 | Excessive | Buffer overflow | ANGLE | 536581050 | |
| CVE-2026-76043 | Excessive | Incorrect calculation | V8 | Raghav Maheshwari | 539350801 |
| CVE-2026-76041 | Excessive | Info leak | Skia | 540027341 | |
| CVE-2026-76047 | Excessive | Kind confusion | V8 | ywatanabee | 541251902 |
| CVE-2026-76038 | Excessive | Kind confusion | V8 | un3xploitable && GF | 541926503 |
| CVE-2026-76045 | Excessive | Use-after-free | WebGL | OpenAI Codex Safety (amyb) | 543082390 |
Customers can replace Chrome by opening the browser menu, deciding on Assist, then About Google Chrome. Chrome will routinely test for the newest obtainable construct and immediate customers to relaunch as soon as the replace has downloaded.
Organizations ought to guarantee managed Home windows, macOS, and Linux endpoints obtain the brand new Chrome model by way of their regular patch-management course of.
Safety groups also needs to monitor browser model compliance, notably on programs that commonly entry untrusted web sites or use web-based graphics purposes.
Google’s printed launch notes establish the affected builds and make sure that the replace comprises 15 safety fixes, together with two vital buffer overflow vulnerabilities in WebGL and Daybreak.
Strengthen Your SOC by Accelerating Menace Detection & Fast Investigations. -> Integrate ANY.RUN With Your SOC Now.