Google Chrome 151 Update Fixes 370 Security Vulnerabilities
The Stable channel has been updated to version 151.0.7922.71.72 for Windows and macOS, while Linux users receive version 151.0.7922.71. The rollout is set to occur over the upcoming days and weeks. According to Google’s security advisory released on July 29, this update encompasses 370 distinct security fixes targeting vulnerabilities in essential browser components, including graphics and networking functionalities.
Access to detailed bug information is temporarily restricted until a majority of users have upgraded. This is a common practice intended to mitigate the risk of active exploitation of vulnerabilities before patches become broadly available. Many of these vulnerabilities were discovered internally by Google’s security teams through automated tools such as AddressSanitizer and MemorySanitizer.
The update resolves seven critical vulnerabilities, identified by CVE numbers ranging from CVE-2026-17650 to CVE-2026-17656. Significant among these are 'use-after-free' issues located in various components, including Compositing and Views, which can be exploited for arbitrary code execution in both renderer and browser processes. Additionally, there are critical flaws stemming from race conditions in the Updater and inadequate validation of untrusted input in graphics libraries like Dawn and ANGLE.
These vulnerabilities increase the risk of sandbox escapes, privilege escalations, or data corruption when attackers manipulate specific states within the browser via malicious content or updates. Alongside the critical vulnerabilities, the Chrome version addresses numerous high-severity issues encountered in subsystems like V8 and Audio, many involving similar use-after-free errors and out-of-bounds accesses that could allow remote code execution or compromise browser integrity.
Furthermore, the update corrects several medium-severity vulnerabilities throughout various subsystems, including Autofill and WebXR, highlighting concerns such as insufficient validation of untrusted inputs and cryptographic weaknesses.
Google's advisory also lists lower-severity vulnerabilities affecting components like NFC and Bluetooth. Although their individual impact may be minor, collectively they highlight the expansive attack surface of Chrome, necessitating ongoing security enhancements.
Google has acknowledged both its internal teams and external researchers for their contributions in identifying these security flaws before the Stable channel releases. Despite the extensive number of fixes in this update, including multiple critical issues related to memory corruption, users and organisations are strongly advised to upgrade to version 151 promptly. This update is crucial for reducing potential exposure to exploitation campaigns targeting these recently disclosed vulnerabilities.
CJP Supports Rahul Gandhi's Claims Against Amit Shah's Actions
Opposition Accuses AAP Government in Punjab of Exam Paper Leaks
Trust Between Government and Youth Essential, Says Wangchuk
Bangladesh's Khalilur Rahman Invites US Secretary Marco Rubio