Chrome 151 patches 370 vulnerabilities

Article by Nacata Security, 30/07/2026

How many security holes can the browser you use every day have?

Chrome 151 arrives with 370 vulnerabilities fixed in one go.

We are not talking about minor flaws: seven had critical severity, the level capable of allowing an attacker to take control of your system without you doing anything unusual.

And 30 of those vulnerabilities lived inside ANGLE, the graphics engine Chrome uses to render everything you see on screen, from videos to web pages.

Visual representation of a use-after-free bug: freed memory fragments floating out of control, illustrating the critical flaws in Compositing, Views, Skia, and ANGLE.
Freed memory, real danger

Seven critical flaws were hiding inside your browser.

Among the critical ones, four use-after-free bugs stand out — a vulnerability that allows already-freed memory to be manipulated to execute malicious code. They affected Compositing, Views, Skia, and Ozone. In addition, two critical insufficient-validation flaws appeared in Dawn and ANGLE, and a critical race condition was hidden in the Updater, the component that manages the browser’s automatic updates.

High-severity bugs also came by the dozen.

More than a dozen of the 71 high-severity flaws were also use-after-free, spread across Navigation, V8, Loader, Autofill, DOM, Audio, and Media. The rest included integer overflow, out-of-bounds read/write, type confusion, and even a cryptographic flaw. The update also closes 170 medium-severity vulnerabilities and 122 low-severity ones, completing a patch of unusually large proportions for Chrome.

Google found 349 of the 370 fixed flaws on its own.

Metaphor of the shared engine among Chromium-based browsers: a central gear driving all the others, with some damaged ones affecting the whole.
Shared engine, collective risk

This does not only affect desktop Chrome.

Edge and Brave share the same engine and key components, meaning the risk extends to millions of additional users.

Sharing a graphics engine also means sharing the attack surface across millions of devices.

So far this year alone, Google has closed more than 1,800 vulnerabilities in Chrome — a figure with no recent precedent.

Updating is not optional, it is urgent.

Chrome 151 is already available as version 151.0.7922.71/.72 for Windows and macOS, and as 151.0.7922.71 for Linux. The browser updates itself, but it is worth verifying that the process has completed before continuing to browse normally.

The bug bounty program also spoke clearly.

Google paid $58,500 in rewards to external researchers who reported 21 flaws. For 13 of those vulnerabilities, the company has not yet disclosed the amount — something common when technical details have not been published to prevent others from exploiting them. This bug bounty model keeps independent researchers continuously reviewing Chrome’s code.

Illustration of Google's bug bounty program: external and internal researchers contributing vulnerabilities in exchange for rewards, with $58,500 distributed in this round.
Bug bounty in action

349 of the 370 flaws were found by Google itself.

That means the majority did not come from outside: internal teams detected them before anyone could exploit them. A fact that reflects well on the internal process, but one that is a reminder of how many flaws can accumulate in a development cycle.

ANGLE concentrated 30 vulnerabilities in a single component.

ANGLE is the open-source WebGL backend that Chrome uses for all graphics rendering. The fact that 30 vulnerabilities are concentrated there is no coincidence: the more a component is exposed to untrusted external content, the greater the attack surface it offers. Every page with images or videos passes through ANGLE.

The most widely used browser never stops patching.

That cumulative figure in Chrome during 2025 says a great deal about the real pace of security in modern software: there is no definitively secure version, only versions that are more up to date than others.

What to do now

  • Open Chrome, go to Settings, and check for version 151.
  • Restart the browser so that the patches are fully applied.
  • If you use Edge or Brave, also check for their pending updates.

When was the last time you checked your browser’s version?

Security is not improvised, it is audited. At Nacata Security we detect vulnerabilities and protect your company, because a single flaw can cost you everything you have built.

Related articles

Nacata Security, reach out to us anytime

How would you rate this news?

We are Nacata Security, get to know us

web: nacata.io

email: info@nacata.io

Phone: 919930793

LinkedIn: Nacata Security

Tools

New versions and features of tools used in offensive and defensive cybersecurity: scanners, exploitation frameworks, auditing software.

For those who want to stay up to date on which tools to use and what has improved.



RATING


7.8



Who are we?


At Nacata Security we are an offensive cybersecurity company specialized in audits and penetration testing.


We detect, assess and help mitigate the vulnerabilities of your systems, networks and applications before a real attacker exploits them, offering 360º defense tailored to each client.


We’d be glad to get in touch with you for whatever you need.