Google has released Chrome version 151.0.7922.108/.109 for Windows and macOS, and version 151.0.7922.108 for Linux.
This update delivers 41 security fixes across various components of the browser, including rendering, graphics, JavaScript, user interface (UI), media, and authentication.
The Stable channel update began rolling out on August 6 and will reach users over the next several days and weeks.
Google Chrome 151 Update
The release addresses six critical-severity memory-safety vulnerabilities. Five of these are use-after-free (UAF) bugs affecting WebGL, Aura, Skia, and Views, while the sixth is an out-of-bounds write issue in ANGLE, Chrome’s graphics translation layer.
Memory-corruption vulnerabilities can be particularly severe, as a malicious website or crafted web content may trigger browser crashes, corrupt memory, or potentially allow arbitrary code execution when combined with other weaknesses.
Independent reports indicate that the update addresses over two dozen memory-safety issues classified as either critical or high severity.
Among the critical vulnerabilities are CVE-2026-19137 and CVE-2026-19170, both UAF vulnerabilities in WebGL. WebGL is a browser API used for hardware-accelerated 2D and 3D web graphics, making it a high-value target for attackers who exploit pages that process malicious graphical content. Other critical issues affect Aura (Chrome’s UI framework), Skia (its graphics library), and Views (another user interface layer).
Additionally, Google has resolved 35 high-severity issues. These include heap buffer overflows in CrashReporting and Base, multiple UAF vulnerabilities in GPU, HTML, V8, Media, Extensions, Payments, Web Authentication, and Skia, as well as integer-overflow issues in GPU and V8.
The patch set also addresses insufficient validation of untrusted input in WebAPKs, Workers, Codecs, UI, and Contextual Tasks.
V8-related problems deserve particular attention because V8 processes JavaScript and WebAssembly. This release fixes inappropriate implementation bugs, a UAF issue, an out-of-bounds write, and an integer overflow in the engine.
Attackers often target browser scripting engines, as successful exploitation can provide an initial foothold in the renderer process before attempting to escape the sandbox or escalate privileges.
Google has kept some bug reports restricted while the update is being propagated, using a common defensive strategy designed to reduce the risk of opportunistic exploitation before users are able to install the patch.
Organizations should prioritize deploying this update on endpoints that access untrusted websites, support sensitive workflows, or use GPU-accelerated web applications.
Administrators can verify the installed version by navigating to the Chrome menu → Help → About Google Chrome. Managed environments should ensure that Windows and macOS devices receive versions 151.0.7922.108/.109, while Linux systems should have version 151.0.7922.108.
Chrome 151 CVE Table
| CVE | Severity | Vulnerability type | Affected component | Reporter / reward |
|---|---|---|---|---|
| CVE-2026-19137 | Critical | Use-after-free | WebGL | Anonymous / TBD |
| CVE-2026-19149 | Critical | Use-after-free | Aura | Google / N/A |
| CVE-2026-19154 | Critical | Use-after-free | Skia | Google / N/A |
| CVE-2026-19157 | Critical | Out-of-bounds write | ANGLE | Google / N/A |
| CVE-2026-19170 | Critical | Use-after-free | WebGL | STAR Labs SG researchers / TBD |
| CVE-2026-19172 | Critical | Use-after-free | Views | Google / N/A |
| CVE-2026-19138 | High | Heap buffer overflow | CrashReporting | Google / N/A |
| CVE-2026-19139 | High | Race condition | CredentialProvider | Google / N/A |
| CVE-2026-19140 | High | Use-after-free | GPU | Google / N/A |
| CVE-2026-19141 | High | Use-after-free | Resources | Google / N/A |
| CVE-2026-19142 | High | Use-after-free | Views | Google / N/A |
| CVE-2026-19143 | High | Insufficient validation | WebAPKs | Google / N/A |
| CVE-2026-19144 | High | Use-after-free | HTML | Google / N/A |
| CVE-2026-19145 | High | Use-after-free | Translate | Google / N/A |
| CVE-2026-19146 | High | Uninitialized use | GPU | Google / N/A |
| CVE-2026-19147 | High | Use-after-free | Aura | Google / N/A |
| CVE-2026-19148 | High | Out-of-bounds write | GPU | Google / N/A |
| CVE-2026-19150 | High | Inappropriate implementation | V8 | Google / N/A |
| CVE-2026-19151 | High | Use-after-free | V8 | Google / N/A |
| CVE-2026-19152 | High | Inappropriate implementation | Navigation | Google / N/A |
| CVE-2026-19153 | High | Insufficient validation | Workers | Google / N/A |
| CVE-2026-19155 | High | Use-after-free | Payments | Google / N/A |
| CVE-2026-19156 | High | Heap buffer overflow | Base | Viktoria Zlatinova / TBD |
| CVE-2026-19158 | High | Use-after-free | Views | Google / N/A |
| CVE-2026-19159 | High | Use-after-free | Views | Google / N/A |
| CVE-2026-19160 | High | Uninitialized use | Skia | Google / N/A |
| CVE-2026-19161 | High | Uninitialized use | Skia | Google / N/A |
| CVE-2026-19162 | High | Out-of-bounds write | V8 | OpenAI Codex Security / TBD |
| CVE-2026-19163 | High | Use-after-free | Media | Google / N/A |
| CVE-2026-19164 | High | Insufficient validation | Codecs | Google / N/A |
| CVE-2026-19165 | High | Use-after-free | Extensions | @bean5oup / TBD |
| CVE-2026-19166 | High | Use-after-free | Web Authentication | heesun / TBD |
| CVE-2026-19167 | High | Integer overflow | GPU | Google / N/A |
| CVE-2026-19168 | High | Inappropriate implementation | V8 | XBOW / $500 |
| CVE-2026-19169 | High | Insufficient validation | Contextual Tasks | Sven Dysthe / $5,000 |
| CVE-2026-19171 | High | Use-after-free | Media | Google / N/A |
| CVE-2026-19173 | High | Out-of-bounds write | Skia | Vu Van Tien / TBD |
| CVE-2026-19174 | High | Integer overflow | V8 | Seunghyun Lee, QED Audit / TBD |
| CVE-2026-19175 | High | Use-after-free | Payments | Google / N/A |
| CVE-2026-19176 | High | Use-after-free | Skia | WinD39 – Huynh Dinh Vu / TBD |
| CVE-2026-19177 | High | Insufficient validation | UI | Fabian Wahle, Hap Security / TBD |
Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

