Chrome 151: Google Fixes Two Critical Security Vulnerabilities; Install the Update Now

Google has launched a brand new safety replace for Chrome, addressing 15 safety vulnerabilities, two of that are rated “important.” Customers of the browser ought to set up the replace to model 151.0.7922.169/.170 as quickly as doable. Vital Chrome safety vulnerabilities normally have an effect on the core of the browser engine and, within the worst case, might be exploited remotely.

What’s behind the replace?

On August 18, 2026, Google rolled out the secure model 151.0.7922.169/.170 for Home windows and macOS, in addition to 151.0.7922.169 for Linux. As ordinary, the replace is rolled out in phases over a number of days to weeks, so in the event you don’t see it immediately, there’s no want to fret. If you happen to don’t wish to wait, you’ll be able to verify for the replace manually (directions beneath).

In whole, the replace addresses 15 vulnerabilities: Google classifies two as important and 13 others as high-severity. Among the many affected parts are the V8 JavaScript engine, the WebGL, Daybreak, and ANGLE graphics libraries, in addition to parts reminiscent of CORS, USB, and the browser’s media part.

An Overview of the Vital Chrome Safety Vulnerabilities

In accordance to Google’s official release notes, the 2 important vulnerabilities every contain buffer overflows in graphics processing. This can be a basic kind of reminiscence error that, within the worst-case situation, might be exploited to execute malicious code.

CVE Severity Part Vulnerability Sort
CVE-2026-76034 Vital WebGL Buffer Overflow
CVE-2026-76036 Vital Daybreak Buffer Overflow
CVE-2026-76038 Excessive V8 Sort Confusion
CVE-2026-76047 Excessive V8 Sort Confusion
CVE-2026-76043 Excessive V8 Incorrect Calculation
CVE-2026-76045 Excessive WebGL Use-after-free
CVE-2026-76040 Excessive Browser Use-after-free
CVE-2026-76046 Excessive ANGLE Buffer Overflow

The remaining entries on the checklist embrace, amongst different issues, a flawed CORS implementation, a race situation within the USB stack, an incorrect reference decision within the core space, and an data leak within the Skia graphics library. Google detected many of the vulnerabilities internally utilizing its personal fuzzing instruments, reminiscent of AddressSanitizer and libFuzzer. Two studies got here from exterior safety researchers, together with a tip from OpenAI’s inner safety division.

Is any of those vulnerabilities already being actively exploited?

No. Neither Google’s launch notes nor studies from German tech media shops reminiscent of Deskmodder presently point out that lively assaults are circulating. Nevertheless, this doesn’t change the advice to replace as quickly as doable: As soon as particulars about important reminiscence errors are made public, it’s normally solely a matter of time earlier than attackers develop appropriate exploits.

Methods to Replace Chrome

You’ll be able to manually set off the replace to Chrome 151.0.7922.169/.170 in just some steps if it hasn’t been put in routinely but:

  1. Open Chrome and click on the three dots within the top-right nook
  2. ChooseSettings, then go to ” About Chrome ” on the left
  3. Chrome will routinely verify for updates and set up the brand new model
  4. Reload the browser by clicking the “Relaunch ” button to activate the replace

Solely the restart really patches the vulnerabilities. Till then, the previous, susceptible model continues to run within the background.

Are Edge, Courageous, and others additionally affected?

Since Microsoft Edge, Courageous, Opera, and Vivaldi run on the identical Chromium framework as Chrome, among the patched vulnerabilities (notably these in V8 and the graphics parts) may be current in these browsers. Expertise reveals that the distributors usually comply with up with their very own updates, normally with a delay of some days. It’s subsequently additionally value manually checking the replace settings for these browsers.

Conclusion

Two important and 13 high-severity safety vulnerabilities without delay is an unusually massive batch for a single Chrome replace. Despite the fact that no lively exploitation is presently recognized, this Chrome safety vulnerability warrants a direct replace—the hassle required is restricted to a restart, whereas the chance of not updating is probably going considerably increased.

Sources: Google Chrome Releases Blog

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *