Google Chrome 151 Fixes 41 Security Flaws, Including 6 Critical Memory Bugs

Google has launched Chrome 151 to the Secure channel, fixing 41 security vulnerabilities, together with six important memory-safety flaws that would allow browser crashes, reminiscence corruption, or malicious code execution.

Chrome 151.0.7922.108/.109 is rolling out for Home windows and macOS methods, whereas Linux customers are receiving model 151.0.7922.108.

Google stated the discharge shall be delivered to customers progressively over the approaching days and weeks. Customers are suggested to replace as quickly as the brand new model turns into obtainable.

Probably the most critical bugs patched on this launch are use-after-free vulnerabilities. These flaws happen when software program continues to entry reminiscence after it has been launched.

An attacker could exploit such weaknesses by convincing a goal to go to a specifically crafted web site or work together with malicious net content material.

Two important use-after-free points have an effect on WebGL, Chrome’s expertise for rendering interactive 2D and 3D graphics in net pages. They’re tracked as CVE-2026-19137 and CVE-2026-19170.

Chrome 151 Vulnerabilities

The primary was reported anonymously, whereas the second was found by Muhammad Alifa Ramdhan, Pan ZhenPeng, and Billy Jheng Bing Jhong of STAR Labs SG Pte. Ltd. Different important flaws embrace CVE-2026-19149, a use-after-free bug in Aura, Chrome’s consumer interface framework.

CVE-2026-19154, a use-after-free vulnerability within the Skia graphics library, and CVE-2026-19172, a use-after-free flaw in Views, one other Chrome interface element.

Google additionally resolved CVE-2026-19157, an out-of-bounds write vulnerability in ANGLE, the graphics translation layer utilized by Chrome. As well as, the replace patches 35 high-severity vulnerabilities affecting a broad vary of browser elements.

These embrace Chrome’s V8 JavaScript engine, GPU course of, HTML renderer, media subsystem, Net Authentication implementation, extensions platform, fee options, translation service, staff, codecs, navigation dealing with, and crash-reporting features.

A number of of the high-severity bugs are memory-related, together with heap buffer overflows, out-of-bounds writes, integer overflows, use of uninitialized reminiscence, and extra use-after-free points.

Important Vulnerabilities Patched

CVE Affected Element
CVE-2026-19137 WebGL (Use-after-free)
CVE-2026-19149 Aura (Use-after-free)
CVE-2026-19154 Skia (Use-after-free)
CVE-2026-19157 ANGLE (Out-of-bounds write)
CVE-2026-19170 WebGL (Use-after-free)
CVE-2026-19172 Views (Use-after-free)

Such bugs are particularly essential as a result of net browsers course of untrusted knowledge from web sites, ads, downloaded recordsdata, scripts, and extensions.

Among the many externally reported points, Google awarded $5,000 for CVE-2026-19169, an inadequate validation flaw in Contextual Duties reported by safety researcher Sven Dysthe.

Researchers from OpenAI Codex Safety, Hap Safety, QED Audit, and different unbiased contributors have been additionally credited with reporting vulnerabilities that have been fastened on this launch.

Google has withheld technical details and proof-of-concept data for the vulnerabilities till most customers replace Chrome, aiming to scale back the danger of attackers exploiting unpatched methods.

Chrome customers can replace the browser by opening the Chrome menu, deciding on Assist, after which selecting About Google Chrome. The browser will examine for the most recent model and immediate the consumer to relaunch after set up.

Organizations ought to prioritize deploying Chrome 151 throughout managed Home windows, macOS, and Linux endpoints to scale back publicity to those high-impact browser vulnerabilities.

 Strengthen Your SOC by Accelerating Risk Detection & Speedy Investigations. -> Integrate ANY.RUN With Your SOC Now.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *