Google has rolled out a major Chrome Stable Channel update, patching 370 security vulnerabilities across the browser’s rendering, graphics, and media subsystems, including several critical and high-severity bugs affecting components such as ANGLE, V8, Skia, and Audio.
The update pushes Chrome to version 151.0.7922.71/.72 on Windows and Mac, and 151.0.7922.71 on Linux. Seven critical-severity flaws headline this release; most are use-after-free bugs that could allow attackers to execute code remotely if exploited.
Google Chrome Fixes 370 Security Flaws
| Severity | Approx. Count |
|---|---|
| Critical | 7 |
| High | ~90 |
| Medium | ~170 |
| Low | ~100 |
These include CVE-2026-17650 (use-after-free in Compositing), CVE-2026-17651 (insufficient input validation in Dawn), CVE-2026-17652 (use-after-free in Views), CVE-2026-17653 (use-after-free in Skia).
CVE-2026-17654 (a race condition in Updater), CVE-2026-17655 (insufficient validation in ANGLE), and CVE-2026-17656 (use-after-free in Ozone). All seven critical issues were discovered internally by Google’s own security team rather than external researchers.
Among the roughly 90 high-severity fixes, the update addresses a use-after-free vulnerability in the Audio component, tracked as CVE-2026-17708, as well as multiple type confusion bugs affecting ANGLE (CVE-2026-17687, CVE-2026-17697) and a separately flagged type confusion issue in the Tab component (CVE-2026-17866).
These memory-safety classes type confusion and use-after-free are frequently chained together in real-world browser exploitation, since they let attackers manipulate object types or freed memory to hijack program execution.
High-severity rewards this cycle included a $36,000 payout for a use-after-free in Navigation and a $1,000 bounty for a use-after-free in V8 reported in collaboration with OpenAI Codex Security.
The bulk of the 370 fixes fall into medium and low severity tiers, covering issues in Autofill, Passwords, DevTools, WebXR, Extensions, and Chrome for iOS, many of which involve insufficient policy enforcement, side-channel information leakage, and inappropriate implementation flaws.
Notably, a $10,000 bounty went to a researcher for an inappropriate implementation bug in Extensions, while smaller rewards covered heap buffer overflow and side-channel issues in Dawn and Autofill, respectively.
Google’s 370-fix update follows a pattern of unusually large Chrome security batches in 2026, including a 382-fix release in June and a 27-fix update earlier in July, reflecting Google’s accelerated internal bug-hunting using AddressSanitizer, MemorySanitizer, and libFuzzer.
| CVE ID | Severity | Component | Issue Type |
|---|---|---|---|
| CVE-2026-17650 | Critical | Compositing | Use after free |
| CVE-2026-17651 | Critical | Dawn | Insufficient validation of input |
| CVE-2026-17652 | Critical | Views | Use after free |
| CVE-2026-17653 | Critical | Skia | Use after free |
| CVE-2026-17654 | Critical | Updater | Race condition |
| CVE-2026-17655 | Critical | ANGLE | Insufficient validation of input |
| CVE-2026-17656 | Critical | Ozone | Use after free |
| CVE-2026-17657 | High | Navigation | Use after free |
| CVE-2026-17658 | High | V8 | Use after free |
| CVE-2026-17659 | High | SiteIsolation | Inappropriate implementation |
| CVE-2026-17660 | High | Network | Insufficient validation of input |
| CVE-2026-17661 | High | Loader | Use after free |
| CVE-2026-17662 | High | Prefetch | Insufficient policy enforcement |
| CVE-2026-17663 | High | GPU | Insufficient validation of input |
| CVE-2026-17664 | High | Loader | Insufficient validation of input |
| CVE-2026-17665 | High | V8 | Use after free |
| CVE-2026-17666 | High | Enterprise | Cryptographic flaw |
| CVE-2026-17667 | High | ANGLE | Uninitialized use |
| CVE-2026-17668 | High | ANGLE | Uninitialized use |
| CVE-2026-17669 | High | Chrome for iOS | Inappropriate implementation |
| CVE-2026-17670 | High | Views | Use after free |
| CVE-2026-17671 | High | ANGLE | Insufficient validation of input |
| CVE-2026-17672 | High | Chromecast | Insufficient validation of input |
| CVE-2026-17673 | High | QUIC | Integer overflow |
| CVE-2026-17674 | High | HTML | Inappropriate implementation |
| CVE-2026-17675 | High | ANGLE | Out-of-bounds write |
| CVE-2026-17676 | High | ANGLE | Inappropriate implementation |
| CVE-2026-17677 | High | ANGLE | Inappropriate implementation |
| CVE-2026-17678 | High | ANGLE | Out-of-bounds read |
| CVE-2026-17679 | High | Print Preview | Insufficient validation of input |
| CVE-2026-17680 | High | Color | Heap buffer overflow |
| CVE-2026-17681 | High | WebAuthn | Insufficient validation of input |
| CVE-2026-17682 | High | ANGLE | Integer overflow |
| CVE-2026-17683 | High | ANGLE | Inappropriate implementation |
| CVE-2026-17684 | High | Chrome for iOS | Insufficient validation of input |
| CVE-2026-17685 | High | Autofill | Use after free |
| CVE-2026-17686 | High | Passwords | Insufficient validation of input |
| CVE-2026-17687 | High | ANGLE | Type confusion |
| CVE-2026-17688 | High | Input | Use after free |
| CVE-2026-17689 | High | ANGLE | Uninitialized use |
| CVE-2026-17690 | High | Insufficient validation of input | |
| CVE-2026-17691 | High | ANGLE | Out-of-bounds write |
| CVE-2026-17692 | High | DataTransfer | Use after free |
| CVE-2026-17693 | High | FileSystem | Inappropriate implementation |
| CVE-2026-17694 | High | DOM | Use after free |
| CVE-2026-17695 | High | ANGLE | Inappropriate implementation |
| CVE-2026-17696 | High | Media | Side-channel information leakage |
| CVE-2026-17697 | High | ANGLE | Type confusion |
| CVE-2026-17698 | High | UI | Insufficient validation of input |
Security teams and end users should update Chrome immediately to versions 151.0.7922.71/.72, since several of the patched bugs are memory-corruption classes that historically attract active exploitation.
Enterprises running managed Chrome fleets should prioritize deployment given the presence of multiple critical use-after-free issues discovered directly by Google’s internal red team.
Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN.