Google has released Chrome version 151.0.7922.71/.72 for Windows and macOS, and 151.0.7922.71 for Linux, addressing 370 security vulnerabilities. The update is rolling out over the coming days and weeks.
This release includes fixes for seven critical vulnerabilities, identified as CVE-2026-17650 through CVE-2026-17656. These include use-after-free issues in components like Compositing, Views, Skia, and Ozone, which can lead to arbitrary code execution. Other critical flaws involve race conditions in the Updater and insufficient validation of untrusted input in graphics libraries such as Dawn and ANGLE.
In addition to the critical vulnerabilities, the update addresses numerous high-severity issues across components like V8, Navigation, QUIC, Audio, Media, WebGL, and Downloads. These issues involve use-after-free errors, out-of-bounds reads/writes, integer overflows, and type confusion scenarios that could enable remote code execution or compromise browser integrity.
Medium-severity flaws have also been resolved in subsystems such as ANGLE, Autofill, DevTools, Extensions, WebXR, WebView, and Passwords. These vulnerabilities range from insufficient validation of untrusted input to policy bypasses and cryptographic weaknesses, potentially leading to data leakage or exploitation of browser features.
Google credits both its internal teams and external security researchers for identifying these vulnerabilities. Many issues were discovered during development before reaching the Stable channel. Given the extensive number of fixes, users and enterprises are strongly encouraged to update Chrome to version 151 promptly to reduce exposure to potential exploitation campaigns targeting these vulnerabilities.
This update underscores the importance of regular software updates in maintaining cybersecurity. With the increasing complexity of web technologies, browsers like Chrome are frequent targets for attackers. Staying current with updates is essential for protecting personal and organizational data from emerging threats.