VYPR
Vypr IntelligenceAI-generatedJul 30, 2026· 25 CVEs

Google Chrome: 25 Vulnerabilities Patched in Single July 30, 2026 Disclosure

Google Chrome version 151.0.7922.72 patches 25 vulnerabilities disclosed on July 30, 2026, affecting core components and features.

Key findings

  • Google Chrome version 151.0.7922.72 addresses 25 vulnerabilities disclosed on July 30, 2026.
  • Vulnerabilities include Use-after-free, Inappropriate implementation, and Insufficient validation flaws across multiple components.
  • Impacts range from arbitrary code execution and sandbox escapes to data leaks and UI spoofing.
  • Two High severity vulnerabilities were patched, alongside numerous Medium and Low severity issues.
  • Users are urged to update to Chrome 151.0.7922.72 to protect against these threats.

On July 30, 2026, Google released Chrome version 151.0.7922.72, addressing a significant batch of 25 vulnerabilities disclosed on the same day. These vulnerabilities span various components of the browser, including its rendering engine, input handling, and specific features like NFC, Bluetooth, and WebAppInstalls. The disclosures highlight potential risks ranging from arbitrary code execution and sandbox escapes to UI spoofing and cross-origin data leaks, underscoring the continuous need for timely security updates in widely used web browsers.

Several vulnerabilities fall under the category of "Use after free," a common memory corruption issue. These include CVE-2026-17719, CVE-2026-17670, CVE-2026-17947, CVE-2026-17918, CVE-2026-17967, and CVE-2026-17737. These flaws, affecting components like Input, Views, WebSockets, Sync, Chrome for iOS, and Bluetooth, could allow remote attackers to execute arbitrary code within the sandbox or perform sandbox escapes.

Another significant group of vulnerabilities involves "Inappropriate implementation" in various components. This includes issues in Crypto (CVE-2026-17865), Blink (CVE-2026-17754, CVE-2026-17962), Favicons (CVE-2026-17859), WebAppInstalls (CVE-2026-17819), CSS (CVE-2026-17878), MediaRecording (CVE-2026-17800), Google Lens (CVE-2026-18006), Browser (CVE-2026-17863), and CORS (CVE-2026-17957). These flaws can lead to diverse impacts such as sandbox escapes, UI spoofing, cross-origin data leaks, arbitrary script injection (UXSS), and privilege escalation.

The batch also includes vulnerabilities related to "Insufficient policy enforcement" or "Insufficient validation of untrusted input." CVE-2026-17910 and CVE-2026-17986, affecting NFC and Bluetooth respectively, could lead to cross-origin data leaks or same-origin policy bypasses. Similarly, CVE-2026-17741 in WebView and CVE-2026-17809 in Extensions highlight risks of sandbox escapes due to insufficient input validation.

The severity of these vulnerabilities varies, with two marked as High (CVE-2026-17719, CVE-2026-17670), several as Medium (including CVE-2026-17865, CVE-2026-17822, CVE-2026-17754, CVE-2026-17859, CVE-2026-17819, CVE-2026-17878, CVE-2026-17800, CVE-2026-17836, CVE-2026-17758, CVE-2026-17770, CVE-2026-17809, CVE-2026-17811, CVE-2026-17863, CVE-2026-17737, CVE-2026-17741), and the rest as Low. All these issues were addressed in Chrome version 151.0.7922.72. Users are strongly advised to update to this version to mitigate the risks associated with these newly disclosed vulnerabilities.

This coordinated disclosure event on July 30, 2026, emphasizes the ongoing security efforts by Google and the Chromium project to identify and patch vulnerabilities. While no specific threat actors or in-the-wild exploitation were mentioned in the provided details, the breadth of affected components and the potential for sandbox escapes and code execution highlight the importance of prompt patching for all users to maintain browser security and protect against potential attacks. The release of version 151.0.7922.72 is crucial for safeguarding against these diverse security threats.

AI-written article. Grounded in 25 CVE records listed below.