Threat reportVulnerabilityTL-2026-1026
Chrome 151 Security Update Patches 382 Vulnerabilities, Including 15 Critical Memory-Corruption Flaws (CVE-2026-13774 to CVE-2026-13788)
Chrome 151 Security Update Patches 382 Vulnerabilities (TL-2026-1026), also tracked as Chrome 151 Stable Channel Update, is a critical-severity software vulnerability, first published 2026-07-01. It has no confirmed attribution, affects Google Chrome (Windows), references 15 CVEs (CVE-2026-13774, CVE-2026-13775, CVE-2026-13776), maps to 16 MITRE ATT&CK techniques (T1005, T1068, T1071), and is covered by 9 detection rules and 17 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 15Referenced vulnerabilities
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 17Indicators of compromise
Key facts for TL-2026-1026
- Threat ID
- TL-2026-1026
- Also known as
- Chrome 151 Stable Channel Update, Chrome 150.0.7871.46/47 Security Fixes
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- all-sectors, government administration, finance, health, technology, education, retail, critical-infrastructure
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 17
How Chrome 151 Security Update Patches 382 Vulnerabilities works
Google's Chrome 151 stable release (desktop build 150.0.7871.46/47, July 1, 2026, for Windows, macOS, Linux and iOS) fixes 382 security defects, including 15 Critical-severity memory-corruption bugs spanning Extensions, GPU, Dawn, WebUSB, Chromoting, ANGLE, Skia, Browser, Views, Bluetooth, Ozone, iOSWeb, and Fullscreen components. Most Criticals are use-after-free (CWE-416) flaws; the rest are type-confusion and insufficient input-validation defects that could enable sandbox escape, heap corruption, or arbitrary code execution via a crafted extension, page, or USB/Bluetooth device interaction.
On July 1, 2026, Google promoted Chrome 151 (Windows/Mac/Linux desktop build 150.0.7871.46, and a closely-tracked 150.0.7871.47 fix build referenced in at least one Chromium issue) and the corresponding Chrome for iOS build to the stable channel, resolving 382 total security issues reported through Chrome's Vulnerability Rewards Program (VRP) and internal fuzzing/sanitizer runs (AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer). Fifteen of the fixes carry Chromium's Critical severity rating, the highest category reserved for bugs that could let a remote attacker escape the renderer sandbox or execute arbitrary code with minimal user interaction.
The Critical set is dominated by use-after-free (CWE-416) defects: CVE-2026-13774 in the Extensions subsystem (reported 2026-04-26) allows an attacker who convinces a victim to install a malicious/crafted Chrome extension to execute arbitrary code by triggering a dangling-pointer access after an extension-related object is freed but still referenced by a callback or message handler. CVE-2026-13775 (GPU process, reported 2026-05-10), CVE-2026-13778 (WebUSB, 2026-05-14), CVE-2026-13779 and CVE-2026-13787 (Chromoting, remote-desktop component, 2026-05-14 and 2026-06-11), CVE-2026-13782 (Browser process core, 2026-05-26), CVE-2026-13783/CVE-2026-13784 (Views UI toolkit, 2026-05-27), CVE-2026-13785 (Bluetooth stack, 2026-05-27), CVE-2026-13786 (Ozone platform abstraction layer, 2026-05-29), and CVE-2026-13788 (Fullscreen API, 2026-06-12) all follow the same pattern: an object (buffer, handler, device session, or UI widget) is freed while a reference to it survives in another code path, and a subsequent access re-enters freed heap memory that an attacker can groom and reclaim with attacker-controlled data, corrupting adjacent heap structures or hijacking a vtable/function pointer to redirect control flow.
The remaining Criticals are type-confusion and validation bugs: CVE-2026-13776 (Dawn, Chrome's cross-platform WebGPU implementation, 2026-05-14) is a type-confusion flaw where a WebGPU object is treated as an incompatible type, allowing memory corruption when GPU commands are dispatched against a mis-typed resource. CVE-2026-13777 (iOSWeb, 2026-05-14) and CVE-2026-13780 (ANGLE, Chrome's GL/Vulkan translation layer, 2026-05-19) and CVE-2026-13781 (Skia, the 2D graphics rendering library, 2026-05-25) are each insufficient-validation flaws where attacker-supplied dimensions, buffer sizes, or resource handles are not fully bounds-checked before use, leading to out-of-bounds memory access during rendering or graphics-command processing.
All 15 issues share a common exploitation narrative that Chromium engineers flagged: a crafted, attacker-controlled web page (or, for Extensions/Chromoting/Bluetooth/WebUSB, a crafted extension package, remote-desktop session, or paired hardware device) triggers the memory-safety violation inside a renderer, GPU, or utility process. Because Chrome's multi-process sandbox isolates the renderer from the browser process and the OS, a UAF or type-confusion bug alone typically yields renderer-level code execution; combined with a privilege-escalation or sandbox-escape primitive (several of these bugs, e.g. in Views/Browser-process code, execute outside the renderer sandbox boundary), an attacker chain could achieve full browser compromise and code execution with the logged-in user's OS privileges, consistent with classic Chrome drive-by-compromise campaigns.
As of this analysis, none of the 15 CVEs (CVE-2026-13774 through CVE-2026-13788) appear in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no public proof-of-concept exploit code has been located. Google's standard coordinated-disclosure policy keeps full bug-tracker details (Chromium issue tracker entries, e.g. issues.chromium.org/issues/506558270 for CVE-2026-13774) access-restricted until a majority of the Chrome user base has received the update, which is standard practice and does not itself indicate active exploitation. The severity classification, breadth (382 total fixes across dozens of subsystems), and historical pattern of Chrome UAF bugs being weaponized within weeks of disclosure (as seen in prior 2026 Chrome releases, e.g. CVE-2026-9873/9874 in the May 2026 148.0.7778 release) are the basis for this threat's CRITICAL severity and ACTIVE tracking status, independent of confirmed in-the-wild exploitation.
Beyond the 15 Criticals, the release also addresses numerous High-severity issues across Chromecast, QUIC, the Chrome Updater, SVG rendering, Safe Browsing, Accessibility APIs, Canvas, File Input handling, and enterprise-management features, plus hundreds of Medium/Low issues in Web Authentication (WebAuthn), WebHID, WebXR, DevTools, Autofill, PDF handling, media Codecs, font parsing, Storage APIs, and the Gamepad API — collectively indicating this was one of the largest single-release vulnerability batches in the browser's 2026 patch history.
MITRE ATT&CK techniques used in TL-2026-1026
Collection
T1005 Data from Local System; T1185 Browser Session Hijacking
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071 Application Layer Protocol
Defense Evasion
T1140 Deobfuscate/Decode Files or Information; T1211 Exploitation for Stealth
Persistence
Initial Access
T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application
Execution
T1203 Exploitation for Client Execution; T1204 User Execution
Impact
T1499 Endpoint Denial of Service
Discovery
Resource Development
T1583 Acquire Infrastructure; T1587 Develop Capabilities
Reconnaissance
Affected products and versions in Chrome 151 Security Update Patches 382 Vulnerabilities
- Google — Chrome (Windows)
Vulnerable versions: < 150.0.7871.46
Fixed in: 150.0.7871.46; 150.0.7871.47 - Google — Chrome (macOS)
Vulnerable versions: < 150.0.7871.46
Fixed in: 150.0.7871.46; 150.0.7871.47 - Google — Chrome (Linux)
Vulnerable versions: < 150.0.7871.46
Fixed in: 150.0.7871.46; 150.0.7871.47 - Google — Chrome for iOS
Vulnerable versions: prior stable build
Fixed in: July 1, 2026 stable release - Google — Chromium (open-source upstream)
Vulnerable versions: pre-fix trunk/branch revisions
Fixed in: 150.0.7871.46+ merge
Remediation for Chrome 151 Security Update Patches 382 Vulnerabilities
Patches
- Google Chrome 151 stable (150.0.7871.46 Windows/Mac/Linux; 150.0.7871.47 fix build referenced for CVE-2026-13774) — apply via chrome://settings/help or managed update channel
- Chrome for iOS corresponding July 1, 2026 stable release
Immediate actions
- Update Google Chrome to version 151 (desktop build 150.0.7871.46/47 or later) on Windows, macOS, and Linux immediately
- Update Chrome for iOS to the corresponding patched build via the App Store
- Force-update managed fleets via Chrome Enterprise policy (Chrome Browser Cloud Management / GPO ForceEnabledExtensions and update policies) rather than waiting for the default staged rollout
- Restart all Chrome/Chromium-based browser processes after update to ensure the patched binary is loaded (in-memory old processes remain vulnerable until restarted)
- Audit and restrict installation of unverified/unlisted Chrome extensions given CVE-2026-13774 requires a malicious extension install
- Disable or tightly control Chrome Remote Desktop / Chromoting usage until patched, given two Critical UAFs (CVE-2026-13779, CVE-2026-13787) reside in that component
- Restrict WebUSB and Web Bluetooth permissions via enterprise policy (DefaultWebUsbGuardSetting, DefaultWebBluetoothGuardSetting) pending patch deployment
Workarounds
- If immediate patching is not possible, disable Chrome Remote Desktop (Chromoting) and WebUSB/Web Bluetooth site permissions fleet-wide
- Restrict extension installation to an enterprise-managed allow-list to mitigate CVE-2026-13774
Longer-term hardening
- Deploy endpoint detection with browser-process and renderer-process crash/anomaly monitoring to catch heap-spray/UAF exploitation attempts
- Enforce Chrome Enterprise auto-update policies with minimal staged-rollout delay for Critical-rated releases
- Maintain an internal extension allow-list and block Chrome Web Store installs outside vetted extensions
- Track Chromium security release notes and CISA KEV additions for these CVE IDs to detect any future move to confirmed in-the-wild exploitation
- Implement site isolation and strict-site-isolation policies to increase the difficulty of cross-origin exploitation chains
CVEs associated with Chrome 151 Security Update Patches 382 Vulnerabilities
Weaknesses (CWE) in Chrome 151 Security Update Patches 382 Vulnerabilities
Timeline of Chrome 151 Security Update Patches 382 Vulnerabilities
- CVE-2026-13774 (use-after-free in Chrome Extensions) reported to Google via the Chrome Vulnerability Rewards Program
- CVE-2026-13775 (use-after-free in GPU process) reported to Google
- Four additional Critical bugs reported the same week: CVE-2026-13776 (Dawn type confusion), CVE-2026-13777 (iOSWeb insufficient validation), CVE-2026-13778 (WebUSB use-after-free), and CVE-2026-13779 (Chromoting use-after-free)
- CVE-2026-13780 (ANGLE insufficient validation) reported
- CVE-2026-13781 (Skia insufficient validation) reported
- CVE-2026-13782 (Browser process use-after-free) reported
- Three Critical bugs reported: CVE-2026-13783 and CVE-2026-13784 (Views UI toolkit use-after-free) and CVE-2026-13785 (Bluetooth stack use-after-free)
- CVE-2026-13786 (Ozone platform layer use-after-free) reported
- CVE-2026-13787 (second Chromoting use-after-free) reported
- CVE-2026-13788 (Fullscreen API use-after-free), the final Critical bug in this batch, reported
- CISA KEV catalog snapshot (1,630 entries) reviewed; none of the 15 CVE-2026-137xx IDs present, indicating no confirmed in-the-wild exploitation as of this date
- Google published the Chrome Releases stable-channel-update blog post for the Chrome 151 / 150.0.7871.46 build
- Cyber Security News publishes coverage of the 382-vulnerability Chrome 151 release, flagging the 15 Critical memory-corruption bugs as the hunt trigger for this threat record
- Chrome 151 stable (150.0.7871.46 desktop, 150.0.7871.47 fix build, and Chrome for iOS) released to Windows, macOS, Linux and iOS users, patching all 382 vulnerabilities including the 15 Criticals
Sources cited for Chrome 151 Security Update Patches 382 Vulnerabilities
- Chrome Update Fixes 382 Vulnerabilities
- Chrome Releases: Stable Channel Update for Desktop
- Chromium Issue Tracker — CVE-2026-13774 (Extensions UAF)
- CISA Known Exploited Vulnerabilities Catalog
- Google Patches 151 Vulnerabilities in Chrome, Including 22 Critical Ones (prior release, May 2026, for comparative pattern)
- Chrome Releases blog index 2026
- Chromium Dash Release Schedule
Detection coverage for TL-2026-1026
As of 2026-07-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1026 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.