Chromium: Nine Vulnerabilities Patched, Including Critical Chromoting Flaw
Key findings • Nine Chromium vulnerabilities disclosed Aug 18-20, 2026, with severity ranging from Medium to Critical. • Critical CVE-2026-76017 (Use after free in Chromoting) allows remote c…

Key findings
- Nine Chromium vulnerabilities disclosed Aug 18-20, 2026, with severity ranging from Medium to Critical.
- Critical CVE-2026-76017 (Use after free in Chromoting) allows remote code execution.
- High-severity flaws in WebGL, USB, and CredentialProvider disclosed Aug 18, patched in v151.0.7922.169.
- Five high-severity vulnerabilities, including buffer overflows and improper resource control, patched Aug 20 in v151.0.7922.173.
- Patches are available in Chrome 151.0.7922.169/.170 and 151.0.7922.173/.174, users urged to update.
On August 18 and 20, 2026, Google released updates for Chromium, patching a batch of nine vulnerabilities disclosed across two days. The vulnerabilities, rated from Medium to Critical, primarily affect core browser components and could allow remote attackers to execute arbitrary code, bypass security policies, or elevate privileges. The most severe flaw, CVE-2026-76017, is a critical use-after-free vulnerability in the Chromoting component that could lead to remote code execution.
Several vulnerabilities were grouped by their affected component or bug class. A cluster of high-severity flaws, including CVE-2026-76045 (Use after free in WebGL), CVE-2026-76044 (Race condition in USB), and CVE-2026-76037 (Link following in CredentialProvider on Windows), were disclosed on August 18. These flaws, with CVSS scores ranging from 8.3 to 8.8, could allow attackers to execute code outside the sandbox. Another vulnerability disclosed on August 18, CVE-2026-76033, is an inappropriate implementation in CORS with a Medium severity rating, which could bypass site isolation.
On August 20, Google patched five more high-severity vulnerabilities. These include CVE-2026-76023 (Improper resource control in Linux Toolkit Theming), CVE-2026-76022 (Buffer overflow in Network), CVE-2026-76019 (Incorrect authorization in Workers), and CVE-2026-76018 (Privilege elevation in Import). These flaws, along with CVE-2026-76017, were addressed in Chrome version 151.0.7922.173 for Windows and macOS, and 151.0.7922.173 for Linux.
The vulnerabilities disclosed on August 18, including CVE-2026-76045, CVE-2026-76044, CVE-2026-76037, and CVE-2026-76033, were fixed in Chrome version 151.0.7922.169 for Windows and macOS, and 151.0.7922.169 for Linux. These updates address a range of issues including use-after-free, race conditions, and improper implementations, with the potential for code execution and sandbox escapes.
Users are urged to update their Chromium-based browsers to the latest versions to mitigate these security risks. The timely patching of these vulnerabilities is crucial for protecting against potential exploitation, which could compromise user data and system integrity. The coordinated disclosure and patching of these nine vulnerabilities highlight the ongoing efforts to secure the browser ecosystem.