Google Chrome: 15 Vulnerabilities Patched, Including Two Critical Flaws
Google Chrome patched 15 vulnerabilities on August 18, 2026, including two critical buffer overflows and multiple high-severity flaws across its components.

Key findings
- Google Chrome patched 15 vulnerabilities on August 18, 2026, including two critical buffer overflows.
- Vulnerabilities span multiple components including V8, WebGL, ANGLE, Dawn, and GPU.
- Critical flaws CVE-2026-76036 and CVE-2026-76034 are buffer overflows.
- The update addresses type confusion, use-after-free, race conditions, and information leaks.
- Users should update to Chrome 151.0.7922.169/.170 to patch these issues.
On August 18, 2026, Google released an update for Chrome addressing a batch of 15 vulnerabilities, including two critical and several high-severity flaws. The update, which brings the stable channel to version 151.0.7922.169/.170 for Windows and Mac, and 151.0.7922.169 for Linux, aims to fix issues ranging from type confusion and buffer overflows to use-after-free vulnerabilities across various components of the browser.
Several vulnerabilities were found in core components and rendering engines. CVE-2026-76047, CVE-2026-76043, and CVE-2026-76038 are type confusion flaws in the V8 JavaScript engine, while CVE-2026-76045 and CVE-2026-76034 are buffer overflows in WebGL. Additionally, CVE-2026-76046, a buffer overflow in ANGLE on Android, and CVE-2026-76036, a critical buffer overflow in Dawn on Android, were patched. Use-after-free vulnerabilities were also addressed, including CVE-2026-76042 in the GPU component and CVE-2026-76040 in the browser on Mac.
The batch also included flaws impacting specific platforms and features. CVE-2026-76044, a race condition in USB, and CVE-2026-76033, an inappropriate implementation in CORS, were among the vulnerabilities fixed. On Windows, CVE-2026-76037, a link-following issue in CredentialProvider, was patched. For Mac users, CVE-2026-76035, an inappropriate implementation in Media, was also addressed. Medium-severity issues include CVE-2026-76041, an information leak in Skia, CVE-2026-76039, an incorrect reference resolution in Core on Android, and CVE-2026-76033, a CORS-related vulnerability.
The most severe issues, CVE-2026-76036 and CVE-2026-76034, are both buffer overflows, with the former in the Dawn component and the latter in WebGL. These critical vulnerabilities, along with numerous high-severity flaws, underscore the importance of timely updates for browser security. While the provided information does not detail active exploitation, the nature of these vulnerabilities suggests a significant risk to users if left unpatched.
Google has addressed these vulnerabilities in the latest stable channel update. Users are strongly advised to update their Chrome browsers to version 151.0.7922.169/.170 to protect themselves from potential attacks. The update process can be initiated manually through the browser's settings or will occur automatically depending on user configuration.
This coordinated disclosure of 15 vulnerabilities highlights ongoing security efforts within Google Chrome. Users should remain vigilant and ensure their browsers are consistently updated to mitigate risks associated with newly discovered flaws. The variety of vulnerabilities patched, from memory corruption to logic errors, emphasizes the complex security landscape of modern web browsers.