TL;DR
Google shipped a large Chrome security update on the Stable channel. It fixes 370 vulnerabilities, including seven rated critical. The new build is 151.0.7922.71/.72 for Windows and Mac, and 151.0.7922.71 for Linux.
- Total: 7 CVEs
- Severity: 7 Unrated
- Actively exploited: None confirmed
- Highest severity: Awaiting analysis — CVE-2026-17650
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-17650 | Awaiting analysis | CWE-416 | 151.0.7922.72 | Not exploited |
| CVE-2026-17651 | Awaiting analysis | CWE-20 | 151.0.7922.72 | Not exploited |
| CVE-2026-17652 | Awaiting analysis | CWE-416 | 151.0.7922.72 | Not exploited |
| CVE-2026-17653 | Awaiting analysis | CWE-416 | 151.0.7922.72 | Not exploited |
| CVE-2026-17654 | Awaiting analysis | CWE-362 | 151.0.7922.72 | Not exploited |
| CVE-2026-17655 | Awaiting analysis | CWE-20 | 151.0.7922.72 | Not exploited |
| CVE-2026-17656 | Awaiting analysis | CWE-416 | 151.0.7922.72 | Not exploited |
Why it matters
Chrome runs on billions of devices worldwide. So a single critical flaw gives attackers a wide target. A booby-trapped web page could trigger some of these bugs during a normal visit.
The scale here stands out. Few browser updates address 370 issues at once. That volume alone makes prompt patching worthwhile.
How the attacks work
Most of the critical bugs are use-after-free flaws. These memory errors can crash the browser or open the door to code execution. They affect core components like Compositing (CVE-2026-17650), Views (CVE-2026-17652), Skia (CVE-2026-17653), and Ozone (CVE-2026-17656).
Two more critical issues stem from weak input validation. CVE-2026-17651 hits the Dawn graphics layer, while CVE-2026-17655 affects ANGLE. A separate race condition, CVE-2026-17654, sits in the Chrome Updater.
Affected versions
Any Chrome build before 151.0.7922.71 is affected. Google reported all seven critical bugs internally. The company is also holding back some bug details until most users update.
Patch and mitigation
Update now. Chrome usually updates itself, but you can force it. Open the menu, then Help, then About Google Chrome. The browser will fetch this Chrome security update and prompt a restart.
Enterprise admins should push the fixed build across managed fleets. For the full list, read the official Chrome Releases advisory. Google has not confirmed any in-the-wild exploitation or public proof-of-concept.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.