VYPR
patchPublished Aug 11, 2026· Updated Aug 12, 2026· 1 source

Chromium: Four High-Severity 'Use After Free' Bugs Patched in Single Chrome Update

Key findings • Four high-severity 'use after free' vulnerabilities were disclosed in Google Chrome on August 11, 2026. • The vulnerabilities affect core components including Blink, HTML, Exte…

Key findings

  • Four high-severity 'use after free' vulnerabilities were disclosed in Google Chrome on August 11, 2026.
  • The vulnerabilities affect core components including Blink, HTML, Extensions, and V8.
  • All flaws were patched in Chrome version 151.0.7922.137.
  • The bugs could allow remote attackers to execute arbitrary code within the browser's sandbox.

On August 11, 2026, Google released Chrome version 151.0.7922.137, patching a batch of four high-severity 'use after free' vulnerabilities that were disclosed on the same day. These vulnerabilities, affecting critical components such as Blink, HTML, Extensions, and V8, collectively pose a significant risk by potentially allowing remote attackers to execute arbitrary code within the browser's sandbox. The timely patching of these flaws is crucial for maintaining user security against potential exploitation.

The disclosed vulnerabilities include:

  • CVE-2026-19560: A use after free flaw in Blink.
  • CVE-2026-19559: A use after free flaw in HTML.
  • CVE-2026-19558: A use after free flaw in Extensions, which could be exploited by a malicious extension installed by a user.
  • CVE-2026-19556: A use after free flaw in the V8 JavaScript engine.

All four vulnerabilities share the same root cause: a use after free error, which can lead to arbitrary code execution within the sandbox environment. The Vypr Intelligence report highlights that these flaws could potentially allow for sandbox escapes, further increasing the risk to users. While the provided information does not specify active exploitation in the wild, the high severity of these bugs necessitates immediate attention.

The vulnerabilities were addressed in Chrome version 151.0.7922.137. Users are strongly advised to update to this version or a later one to protect themselves from potential attacks leveraging these flaws. The consistent patching of such vulnerabilities underscores the ongoing efforts by the Chromium security team to maintain the integrity and safety of the browser.

This batch of disclosures serves as a reminder of the persistent threats targeting web browsers and the importance of prompt security updates. Users of Google Chrome should ensure their browsers are automatically updated or manually update to the latest version to mitigate the risks associated with these and other potential vulnerabilities. The rapid response in patching these high-severity issues demonstrates the commitment to user safety within the Chromium project.

Synthesized by Vypr AI