Google has released Chrome 151 Stable for Windows, macOS, and Linux, fixing seven security vulnerabilities including CVE-2026-76017, a critical use-after-free flaw in Chromoting, the technology behind Chrome Remote Desktop. The update is rolling out as 151.0.7922.173/.174 for Windows and macOS and 151.0.7922.173 for Linux, with Google limiting technical details until more users have installed the patch.
The release also addresses six high-severity bugs across Import, Workers, V8, DOM, Network, and Linux Toolkit Theming, covering weakness types such as privilege elevation, incorrect authorization, race conditions, buffer overflow, and improper resource control. Google said it has not disclosed proof-of-concept exploit code or reported active exploitation, but the flaws could still expose users to compromise through malicious web content, phishing links, advertisements, or other crafted browser-based attacks, making prompt enterprise patching a priority.

See real exploitation activity before you spend the cycle.
10 events from the most recent confirmed update back to the earliest known activity.
Debian LTS issued DLA-4758-1 for Debian 12 "Bookworm," updating Chromium to 151.0.7922.173-1~deb12u1 to remediate CVE-2026-76017 through CVE-2026-76023. The advisory recommended upgrading affected Chromium packages.
Debian issued DSA-6476-1 for Debian 13 "trixie," updating Chromium to 151.0.7922.173-1~deb13u1 to fix CVE-2026-76017 through CVE-2026-76023. Debian recommended upgrading affected Chromium packages.
Google released a Chrome Stable channel update to version 151.0.7922.173/.174 for Windows and Mac and 151.0.7922.173 for Linux, fixing seven vulnerabilities including critical CVE-2026-76017. Google said detailed bug information may remain restricted until most users have updated or dependent third-party libraries are patched.
Keita Sode and Daisuke Hatakeyama of SYZD Research reported CVE-2026-76023, a high-severity improper resource control vulnerability in Linux Toolkit Theming.
0xAlessandro reported CVE-2026-76022, a high-severity buffer overflow vulnerability in Chrome's Network component.
Salvatore Gulizia, also known as Serotav, reported CVE-2026-76020, a high-severity race condition vulnerability in Chrome's V8 JavaScript engine.
Google BigSleep@Grape reported CVE-2026-76021, a high-severity use-after-free vulnerability in Chrome's DOM component.
An anonymous reporter disclosed CVE-2026-76019, a high-severity incorrect authorization vulnerability in Chrome Workers.
Google internally reported CVE-2026-76017, a critical use-after-free vulnerability in Chromoting, the technology behind Chrome Remote Desktop.
Google reported CVE-2026-76018, a high-severity privilege elevation vulnerability in the Import component of Chrome.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
8 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcemalware.news
Open sourcecyber.gc.ca
Open sourceacn.gov.it
Open sourcecybersecuritynews.com
Open sourcechromereleases.googleblog.com
Open sourcecirt.gy
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.