Google has released a Chrome desktop stable-channel update to address 15 security issues, including two critical buffer overflow vulnerabilities that could let a remote attacker achieve arbitrary code execution outside the browser sandbox through a crafted HTML page. The flaws are tracked as CVE-2026-76034 in WebGL and CVE-2026-76036 in Dawn, the graphics library that implements the WebGPU standard, raising the risk that a user could be compromised simply by visiting a malicious or compromised website.
The update brings Chrome to version 151.0.7922.169/.170 on Windows and macOS and 151.0.7922.169 on Linux. The patched vulnerabilities affect desktop Chrome across all three platforms, and the presence of sandbox-escape-capable browser bugs makes the release particularly urgent because successful exploitation could move execution from browser content directly onto the host system.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
The published CVE record for CVE-2026-76036 identified the critical Dawn buffer overflow as affecting Google Chrome on Android versions prior to 151.0.7922.169. The flaw can be exploited via a crafted HTML page to achieve arbitrary code execution outside the sandbox.
Google released a Chrome desktop stable-channel update with 15 security fixes, upgrading Windows and macOS to version 151.0.7922.169/.170 and Linux to 151.0.7922.169. The update fixes two critical buffer overflow vulnerabilities, CVE-2026-76034 in WebGL and CVE-2026-76036 in Dawn, both of which could allow remote code execution outside the browser sandbox via a crafted HTML page.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
5 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcemalwarebytes.com
Open sourcecve.org
Open sourcechromereleases.googleblog.com
Open sourcew3.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.