CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back ◇ Industry News & Leadership Aug 12, 2026

Google Chrome 151 Patches Five High-Severity Use-After-Free Flaws in V8, Blink, and Extensions

Cybersecurity News Archived Aug 12, 2026 ✓ Full text saved

Google has officially released Chrome 151 to the Stable channel, mitigating five high-severity security vulnerabilities impacting key browser engine components, including the V8 JavaScript engine, Blink rendering engine, Chrome Extensions framework, HTML processing layer, and TabStrip. The update is currently rolling out as version 151.0.7922.137/.138 for Windows and macOS, while Linux systems receive version 151.0.7922.137. […] The post Google Chrome 151 Patches Five High-Severity Use-After-Fre

Full text archived locally
✦ AI Summary · Claude Sonnet


    HomeCyber Security News Google Chrome 151 Patches Five High-Severity Use-After-Free Flaws in V8, Blink, and Extensions By Guru Baran August 12, 2026 Google Chrome 151 Patches Five High-Severity Use-After-Free Flaws in V8, Blink, and Extensions Google has officially released Chrome 151 to the Stable channel, mitigating five high-severity security vulnerabilities impacting key browser engine components, including the V8 JavaScript engine, Blink rendering engine, Chrome Extensions framework, HTML processing layer, and TabStrip. The update is currently rolling out as version 151.0.7922.137/.138 for Windows and macOS, while Linux systems receive version 151.0.7922.137. Google noted that the update will reach all users worldwide over the coming days and weeks. Chrome 151 Patches Five High-Severity Flaws All five vulnerabilities addressed in Chrome 151 belong to the use-after-free (UAF) memory safety class, which occurs when software continues to access memory after it has been deallocated. In web browsers, adversaries can attempt to trigger these vulnerabilities using maliciously crafted web scripts, HTML elements, or extension interactions. Depending on the targeted subsystem and exploit environment, successful exploitation can result in browser crashes, sensitive information disclosure, or arbitrary code execution. Security teams tracking ongoing chrome security updates should prioritize applying desktop browser updates across enterprise endpoints. CVE Identifier Affected Subsystem Severity Reported By & Date CVE-2026-19556 V8 JavaScript Engine High Jihyeon Jeong (Compsec Lab, SNU) — July 15, 2026 CVE-2026-19557 TabStrip Interface High Google Internal Discovery — July 14, 2026 CVE-2026-19558 Chrome Extensions High @bean5oup — July 20, 2026 CVE-2026-19559 HTML Processing High Google Internal Discovery — July 28, 2026 CVE-2026-19560 Blink Rendering Engine High WinD39 (Huynh Dinh Vu) — July 30, 2026 The most notable vulnerability resolved in this cycle is CVE-2026-19556, a high-severity UAF flaw in V8, Chrome’s open-source JavaScript and WebAssembly engine. Discovered by research intern Jihyeon Jeong of Compsec Lab at Seoul National University, Google awarded a $500 bug bounty for the finding. Because V8 processes web-supplied JavaScript code, flaws in the V8 engine remain a primary target for browser exploits. As highlighted in the official release post on the Google Chrome Releases Blog, the update also fixes CVE-2026-19560 in the Blink rendering engine (reported by Huynh Dinh Vu / WinD39) and CVE-2026-19558 in the Chrome Extensions API (reported by @bean5oup). Extension APIs and rendering engines hold broad permissions to interact with web content, making memory safety in these layers critical for preventing Chrome RCE vulnerabilities from reaching production systems. Two additional internal findings, CVE-2026-19557 in the TabStrip UI and CVE-2026-19559 in HTML parsing, demonstrate that memory safety risks span both front-end user interface components and core web parsers. In line with standard security protocol, Google has restricted technical details and public proof-of-concept (PoC) information for all five bugs. Details remain restricted until a majority of the active user base updates to Chrome 151, minimizing the risk of threat actors weaponizing patch information against unpatched endpoints. Google credited its security researchers and highlighted its reliance on automated fuzzing and defensive memory testing technologies during development. Desktop Users: Navigate to Help > About Google Chrome to trigger the automatic download of version 151.0.7922.137/.138 and restart the browser. Enterprise Administrators: Verify that managed Windows, macOS, and Linux endpoints receive Chrome 151 through software deployment and patch management platforms. [Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model -> Register Now Tags cyber security news vulnerability Copy URL Linkedin Twitter ReddIt Telegram Guru Baranhttps://cybersecuritynews.com Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments. Cyber Security Guide Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways  Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026) An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response  Latest Cyber News Cyber Security News 737 Fake Chrome VPN Extensions Hijack Browser Traffic Through Attacker-Controlled SOCKS5 Proxies Cyber Security News 2.86 Billion Credentials Flood Criminal Markets as Enterprise Access Moves Upmarket Cyber Security News Fake CCleaner Download Installs GhostDesk Chrome Spyware on Windows PCs Cyber Security News 13-Minute WindRelay Malware Attack Uses SpyNote RAT and NFC Relay Malware to Drain Victim Accounts Cyber Security Nightmare-Eclipse Drops ShieldBreak Windows Defender 0-day Vulnerability Expert Talks Expert Talks From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking  Expert Talks Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage  Expert Talks Your Incident Response Plan Has a Dependency You Never Approved Expert Talks Security in the AI Era Starts with First Principles  Cyber Security News Planning Your AI Security – How will You Manage All Your Resources?
    💬 Team Notes
    Article Info
    Source
    Cybersecurity News
    Category
    ◇ Industry News & Leadership
    Published
    Aug 12, 2026
    Archived
    Aug 12, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗