VYPR
patchPublished Jul 30, 2026· 2 sources

Google Chrome 151 Addresses 370 Vulnerabilities, Including Seven Critical Flaws

Google Chrome 151 has been released with patches for 370 security vulnerabilities, including seven critical bugs affecting key components like Compositing, Views, Skia, and Ozone.

Google has rolled out version 151 of its Chrome browser to the stable channel, delivering fixes for a substantial 370 security vulnerabilities. This update underscores the continuous effort required to maintain the security of one of the world's most widely used web browsers.

The release tackles seven critical-severity bugs, with a significant portion of these being use-after-free vulnerabilities. These critical flaws were identified in core browser components such as Compositing, Views, Skia, and Ozone, indicating potential for serious security compromises if left unaddressed.

Further compounding the critical issues, Chrome 151 also resolves two critical flaws related to insufficient validation of untrusted input in the Dawn and ANGLE graphics engines, alongside a critical race condition vulnerability within the browser's Updater component. These types of vulnerabilities can often be exploited to execute arbitrary code or gain unauthorized access.

Beyond the critical defects, the update addresses over a dozen high-severity vulnerabilities, many of which are also use-after-free issues. These impact a broad range of browser functionalities and components, including Navigation, V8 JavaScript engine, Loader, Views, Autofill, Input, DataTransfer, DOM, ANGLE, Audio, Updater, and Media. The sheer number and variety of high-severity flaws highlight the complexity of securing a modern web browser.

The patch notes also detail numerous other high-severity weaknesses, encompassing categories such as inappropriate implementation, insufficient policy enforcement, insufficient validation of untrusted input, uninitialized use, integer overflow, out-of-bounds read/write, type confusion, policy bypass, race conditions, object lifecycle issues, and cryptographic flaws. This broad spectrum of vulnerabilities suggests a wide attack surface within the browser.

Notably, 30 of the resolved vulnerabilities specifically impact ANGLE (Almost Native Graphics Layer Engine), the open-source backend that Chrome utilizes for all its graphics rendering. This concentration of issues in a key graphics component warrants attention from security professionals.

Google attributes the discovery of 349 of these vulnerabilities to its internal security teams, while external researchers were credited with reporting 21 issues. The company has disbursed $58,500 in bug bounty rewards to these external researchers, with payments for 13 undisclosed flaws pending. Since the beginning of the year, Google has now addressed over 1,800 vulnerabilities in Chrome, reflecting a consistent pace of security patching.

Chrome 151 is now available as versions 151.0.7922.71/.72 for Windows and macOS, and 151.0.7922.71 for Linux. Users are strongly advised to update their browsers as soon as possible to protect against potential exploitation of these newly patched security flaws.

The latest update to Chrome 151, released on July 29, 2026, specifically addresses seven critical vulnerabilities, including multiple 'use after free' bugs in components such as Compositing, Views, Skia, and Ozone. Additionally, the patches cover issues related to insufficient validation of untrusted input in Dawn and ANGLE, as well as a race condition in the Updater, with these critical flaws reported between May 18 and June 14, 2026.

Synthesized by Vypr AI