Chrome 151 fixes 41 critical, high-severity security flaws

Google released Chrome 151 to patch 41 critical and high-severity vulnerabilities, including six critical flaws and 24 memory-safety bugs.
Google released Chrome 151 on Thursday with fixes for 41 critical and high-severity vulnerabilities. The update is rolling out as versions 151.0.7922.108/.109 for Windows and macOS and 151.0.7922.108 for Linux.
The patch set includes six critical-severity flaws and 35 high-severity issues. The critical fixes address five use-after-free defects in WebGL, Aura, Skia and Views, and an out-of-bounds write in the ANGLE graphics engine. Two of the WebGL defects were reported by external researchers; the other four were found by Google engineers.
Of the 35 high-severity issues, 24 are memory-safety bugs, including use-after-free, buffer overflow, out-of-bounds write and uninitialized-use defects. The remaining high-severity flaws involve insufficient validation of untrusted input, incorrect implementations, race conditions and integer overflows.
Google attributed 25 of the high-severity reports to its internal teams and credited outside researchers for the other 10. The company has publicly disclosed two bounty payments of $500 each and has not yet announced rewards for the two externally reported WebGL defects.
Google said it has no evidence that attackers are exploiting these vulnerabilities in the wild and noted that its use of artificial intelligence helped accelerate the patch process for this release.
Users and IT teams should install the update when it appears in Chrome’s built-in updater or push it through enterprise deployment tools. The patched components-WebGL, Aura, Skia, Views and the ANGLE graphics engine-are used to render web graphics and manage windows and input; memory-safety defects in those areas can lead to crashes, data corruption or arbitrary code execution if exploited.
Administrators unable to apply the update immediately are advised to monitor systems for unusual activity and to prioritize devices that handle untrusted web content.







