Google has released Chrome 151 to the Stable channel, fixing 41 security vulnerabilities, including six critical memory-safety flaws that could enable browser crashes, memory corruption, or malicious code execution.
Chrome 151.0.7922.108/.109 is rolling out for Windows and macOS systems, while Linux users are receiving version 151.0.7922.108.
Google said the release will be delivered to users gradually over the coming days and weeks. Users are advised to update as soon as the new version becomes available.
The most serious bugs patched in this release are use-after-free vulnerabilities. These flaws occur when software continues to access memory after it has been released.
An attacker may exploit such weaknesses by convincing a target to visit a specially crafted website or interact with malicious web content.
Two critical use-after-free issues affect WebGL, Chrome’s technology for rendering interactive 2D and 3D graphics in web pages. They are tracked as CVE-2026-19137 and CVE-2026-19170.
Chrome 151 Vulnerabilities
The first was reported anonymously, while the second was discovered by Muhammad Alifa Ramdhan, Pan ZhenPeng, and Billy Jheng Bing Jhong of STAR Labs SG Pte. Ltd. Other critical flaws include CVE-2026-19149, a use-after-free bug in Aura, Chrome’s user interface framework.
CVE-2026-19154, a use-after-free vulnerability in the Skia graphics library, and CVE-2026-19172, a use-after-free flaw in Views, another Chrome interface component.
Google also resolved CVE-2026-19157, an out-of-bounds write vulnerability in ANGLE, the graphics translation layer used by Chrome. In addition, the update patches 35 high-severity vulnerabilities affecting a broad range of browser components.
These include Chrome’s V8 JavaScript engine, GPU process, HTML renderer, media subsystem, Web Authentication implementation, extensions platform, payment features, translation service, workers, codecs, navigation handling, and crash-reporting functions.
Several of the high-severity bugs are memory-related, including heap buffer overflows, out-of-bounds writes, integer overflows, use of uninitialized memory, and additional use-after-free issues.
Critical Vulnerabilities Patched
| CVE | Affected Component |
|---|---|
| CVE-2026-19137 | WebGL (Use-after-free) |
| CVE-2026-19149 | Aura (Use-after-free) |
| CVE-2026-19154 | Skia (Use-after-free) |
| CVE-2026-19157 | ANGLE (Out-of-bounds write) |
| CVE-2026-19170 | WebGL (Use-after-free) |
| CVE-2026-19172 | Views (Use-after-free) |
Such bugs are especially important because web browsers process untrusted data from websites, advertisements, downloaded files, scripts, and extensions.
Among the externally reported issues, Google awarded $5,000 for CVE-2026-19169, an insufficient validation flaw in Contextual Tasks reported by security researcher Sven Dysthe.
Researchers from OpenAI Codex Security, Hap Security, QED Audit, and other independent contributors were also credited with reporting vulnerabilities that were fixed in this release.
Google has withheld technical details and proof-of-concept information for the vulnerabilities until most users update Chrome, aiming to reduce the risk of attackers exploiting unpatched systems.
Chrome users can update the browser by opening the Chrome menu, selecting Help, and then choosing About Google Chrome. The browser will check for the latest version and prompt the user to relaunch after installation.
Organizations should prioritize deploying Chrome 151 across managed Windows, macOS, and Linux endpoints to reduce exposure to these high-impact browser vulnerabilities.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

