TL;DR
Google shipped a Chrome security update on August 26, 2026. It fixes 15 vulnerabilities, including two critical buffer overflows. Both critical bugs sit in the browser’s graphics stack. The new Stable build is 151.0.7922.169/.170.
- Total: 15 CVEs
- Severity: 15 Unrated
- Actively exploited: None confirmed
- Highest severity: Awaiting analysis — CVE-2026-76034
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-76034 | Awaiting analysis | CWE-122 | 151.0.7922.169 | Not exploited |
| CVE-2026-76036 | Awaiting analysis | CWE-122 | 151.0.7922.169 | Not exploited |
| CVE-2026-76033 | Awaiting analysis | CWE-20 | 151.0.7922.169 | Not exploited |
| CVE-2026-76035 | Awaiting analysis | CWE-20 | 151.0.7922.169 | Not exploited |
| CVE-2026-76037 | Awaiting analysis | CWE-59 | 151.0.7922.169 | Not exploited |
| CVE-2026-76038 | Awaiting analysis | CWE-843 | 151.0.7922.169 | Not exploited |
| CVE-2026-76039 | Awaiting analysis | CWE-706 | 151.0.7922.169 | Not exploited |
| CVE-2026-76040 | Awaiting analysis | CWE-416 | 151.0.7922.169 | Not exploited |
Why it matters
Chrome runs on billions of devices, so each Chrome security update carries wide reach. The two critical flaws affect WebGL and Dawn. Both handle graphics, which malicious web content can target. A crafted page could trigger memory corruption.
The two critical bugs are CVE-2026-76034 and CVE-2026-76036. Google’s own team reported both. This Chrome security update also resolves twelve high-severity issues.
How the attack works
Most fixes address memory-safety bugs. The set includes use-after-free flaws in Browser and WebGL. It also patches two V8 type-confusion bugs. An attacker would lure a victim to a malicious page. That page would then abuse the flaw to corrupt memory.
Google confirms no exploitation in the wild for these bugs. Notably, one V8 use-after-free flaw came from OpenAI’s Codex Security team. You can read the full Chrome Stable channel advisory for the CVE list.
Affected versions
Any Chrome build before 151.0.7922.169 is affected. The fix covers Windows, Mac, and Linux. Chromium-based browsers like Edge inherit these flaws too.
Patch and mitigation steps
Update Chrome without delay. Open the menu, then Help, then About Google Chrome. The browser checks for the update and downloads it. Finally, restart Chrome to apply the fix. Managed fleets should confirm the running version rather than trust update policy alone.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.