Threat reportVulnerabilityTL-2026-1770
Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security Flaws Including 7 Critical Sandbox-Escape / Local-Privilege-Escalation Bugs (CVE-2026-17650 – CVE-2026-17656)
Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security (TL-2026-1770) is a critical-severity software vulnerability, first published 2026-07-30. It has no confirmed attribution, affects Google Google Chrome (Windows), references 7 CVEs (CVE-2026-17650, CVE-2026-17651, CVE-2026-17652), maps to 16 MITRE ATT&CK techniques (T1059.007, T1068, T1082), and is covered by 9 detection rules and 29 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 7Referenced vulnerabilities
- Techniques
- 16MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 29Indicators of compromise
Key facts for TL-2026-1770
- Threat ID
- TL-2026-1770
- Severity
- CRITICAL
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, technology, education, critical-infrastructure, retail, general-enterprise
- Target regions
- global
- Detection rules
- 9
- Indicators of compromise
- 29
Malware and tooling in Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security
Malware and tooling: AFL, AddressSanitizer, Control Flow Integrity, MemorySanitizer, UndefinedBehaviorSanitizer, libFuzzer
How Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security works
Google's July 29-30, 2026 Chrome 151 stable channel update (151.0.7922.71/.72 Windows/macOS, 151.0.7922.71 Linux) fixes 370 security issues -- 7 critical, 71 high, 170 medium, 122 low. All 7 critical bugs are confirmed via NVD: four use-after-free flaws (Compositing, Views, Skia, Ozone) and two insufficient-input-validation flaws (Dawn/WebGPU on Android, ANGLE) that enable sandbox escape once a renderer process is already compromised via a crafted HTML page, plus a race condition in the Chrome Updater on macOS enabling local OS-level privilege escalation via a malicious file. No CVE in this batch appears in the CISA KEV catalog and no public PoC or in-the-wild exploitation has been reported.
On July 29-30, 2026, Google published the Chrome 151 stable channel update (chromereleases.googleblog.com), raising the desktop build to 151.0.7922.71/.72 on Windows and macOS and 151.0.7922.71 on Linux, and fixing 370 total security issues (7 critical / 71 high / 170 medium / 122 low per the GBHackers writeup that seeded this threat). The 7 critical issues were independently confirmed against NVD, each carrying a Chromium 'Critical' severity rating and a linked issues.chromium.org tracker entry (still access-restricted, consistent with Google's standard embargo until a majority of users have updated):
- CVE-2026-17650 -- Use-after-free in Compositing (CWE-416): a remote attacker who has already compromised the renderer process can potentially achieve sandbox escape via a crafted HTML page. - CVE-2026-17651 -- Insufficient validation of untrusted input in Dawn (Chrome's WebGPU implementation) on Android (CWE-20): a remote attacker can potentially perform sandbox escape via a crafted HTML page. This is the only one of the seven scoped specifically to Android. - CVE-2026-17652 -- Use-after-free in Views, Chromium's cross-platform UI toolkit (CWE-416): same renderer-compromise-to-sandbox-escape pattern as 17650. - CVE-2026-17653 -- Use-after-free in Skia, Chromium's 2D graphics rendering library (CWE-416): same pattern. - CVE-2026-17654 -- Race condition in the Chrome Updater on macOS (CWE-362): a LOCAL attacker can perform OS-level privilege escalation via a malicious file. This is the only one of the seven that does not require a prior renderer compromise and does not rely on the 'crafted HTML page' vector -- it is a local, file-based TOCTOU-class updater flaw. - CVE-2026-17655 -- Insufficient validation of untrusted input in ANGLE, the graphics translation layer Chrome uses to map WebGL/GPU calls to native graphics APIs (CWE-20): sandbox escape via crafted HTML page. - CVE-2026-17656 -- Use-after-free in Ozone, Chromium's Linux/embedded display-abstraction layer (CWE-416): sandbox escape via crafted HTML page.
Six of the seven (all except the Updater race condition) follow an identical exploit-chain shape documented verbatim in each NVD record: the attacker must first achieve arbitrary code execution inside the sandboxed renderer process (typically via a separate, unpatched renderer-side memory-corruption bug or a scripting-engine flaw, not part of this disclosure), and then trigger the UAF/validation flaw in a lower-privileged-but-still-sandboxed component (Compositing, Views, Skia, Ozone, Dawn, ANGLE) to break out of the Chrome sandbox into the higher-privileged browser process -- i.e., these are second-stage sandbox-escape primitives in a multi-bug exploit chain, not standalone remote-code-execution bugs on their own. This matches the classic Chrome exploit-chain pattern (renderer 1-day/0-day + sandbox-escape 1-day/0-day) used by commercial exploit brokers and APT-affiliated exploit developers.
Google credited a mix of external researchers and internal detection via memory-safety tooling (AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL fuzzing) for the broader 370-bug batch; the source article did not break out individual bounty amounts or named researchers for the 7 critical bugs specifically. Neither the GBHackers source article, the Chrome release blog excerpt, nor a direct CISA KEV catalog check found evidence of active exploitation or a public proof-of-concept for any of the 7 critical CVEs as of 2026-07-30. Given Chrome's dominant global browser market share, the volume of critical memory-safety fixes in a single release, and the fact 6 of 7 are sandbox-escape primitives exploitable via nothing more than a crafted web page (once chained with a renderer bug), this release warrants priority patch rollout even absent confirmed in-the-wild activity.
MITRE ATT&CK techniques used in TL-2026-1770
Execution
T1059.007 JavaScript; T1203 Exploitation for Client Execution; T1204.001 Malicious Link; T1204.002 Malicious File
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism
Discovery
T1082 System Information Discovery
Initial Access
T1189 Drive-by Compromise; T1566.002 Spearphishing Link
Defense Evasion
T1211 Exploitation for Stealth
stealth
T1574.010 Services File Permissions Weakness
Resource Development
T1587.004 Exploits; T1588.005 Exploits; T1588.006 Vulnerabilities; T1608.005 Link Target
Reconnaissance
Affected products and versions in Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security
- Google — Google Chrome (Windows)
Vulnerable versions: < 151.0.7922.71
Fixed in: 151.0.7922.71; 151.0.7922.72 - Google — Google Chrome (macOS)
Vulnerable versions: < 151.0.7922.71
Fixed in: 151.0.7922.71; 151.0.7922.72 - Google — Google Chrome (Linux)
Vulnerable versions: < 151.0.7922.71
Fixed in: 151.0.7922.71 - Google — Google Chrome (Android)
Vulnerable versions: < 151.0.7922.72
Fixed in: 151.0.7922.72 - Google / Chromium Project — Chromium (open-source upstream; affects all downstream Chromium-based browsers pending their own rebase)
Vulnerable versions: < 151.0.7922.71
Fixed in: 151.0.7922.71+
Remediation for Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security
Patches
- Google Chrome 151.0.7922.71/.72 (Windows)
- Google Chrome 151.0.7922.71/.72 (macOS)
- Google Chrome 151.0.7922.71 (Linux)
- Google Chrome 151.0.7922.72 (Android, for CVE-2026-17651)
Immediate actions
- Update Google Chrome to 151.0.7922.71/.72 (Windows), 151.0.7922.71/.72 (macOS), or 151.0.7922.71 (Linux) via chrome://settings/help, then relaunch the browser to load the patched binary.
- For managed/enterprise fleets, push the update via Chrome Enterprise policy (TargetVersionPrefix / auto-update) rather than waiting on end-user relaunch, given 6 of the 7 critical bugs are exploitable via nothing more than visiting a crafted web page once chained with a renderer bug.
- macOS fleets specifically: prioritize rollout given CVE-2026-17654 is a locally-triggerable Updater race condition unique to macOS.
- Android fleets: prioritize rollout given CVE-2026-17651 (Dawn/WebGPU) is Android-specific.
Workarounds
- No official workaround supersedes patching. Disabling WebGPU (chrome://flags -> #enable-unsafe-webgpu / Dawn) reduces exposure to CVE-2026-17651 on Android until patched.
- Disabling GPU/hardware compositing (chrome://flags -> #disable-gpu-compositing) offers partial mitigation for the Compositing UAF (CVE-2026-17650) but degrades rendering performance and is not a substitute for updating.
Longer-term hardening
- Enforce mandatory automatic browser updates via Chrome Enterprise / Chrome Browser Cloud Management so critical patches land within days, not weeks.
- Maintain Site Isolation and renderer-sandbox hardening as defense-in-depth against the class of UAF/sandbox-escape bugs recurring across Compositing, Views, Skia, Ozone, Dawn, and ANGLE.
- Track the CVE-2026-17650 through CVE-2026-17656 range against fleet telemetry (chrome://version reporting) to confirm 100% patch compliance, and re-check CISA KEV periodically in case any of the seven are later added following in-the-wild observation.
CVEs associated with Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security
CVE-2026-17650, CVE-2026-17651, CVE-2026-17652, CVE-2026-17653, CVE-2026-17654, CVE-2026-17655, CVE-2026-17656
Weaknesses (CWE) in Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security
Timeline of Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security
- Google publishes the Chrome 151 Stable Channel Update for Desktop blog post, raising the build to 151.0.7922.71/.72 (Windows/macOS) and 151.0.7922.71 (Linux) and fixing 370 total security issues.
- CISA Known Exploited Vulnerabilities catalog checked directly; none of CVE-2026-17650 through CVE-2026-17656 present, confirming no CISA-confirmed active exploitation as of this analysis.
- TL-Intel-Harness ingests the GBHackers article via the RSS hunt pipeline and opens threat TL-2026-1770.
- GBHackers publishes "Google Chrome 151 Fixes 370 Security Flaws", summarizing all severity tiers and the 7 critical component-level bugs.
- CVE-2026-17656 (use-after-free in Ozone, Chromium issue #523725277) published in NVD as Critical severity.
- CVE-2026-17655 (insufficient validation in ANGLE, Chromium issue #522556145) published in NVD as Critical severity.
- CVE-2026-17654 (race condition in Chrome Updater on macOS, Chromium issue #522314940) published in NVD as Critical severity -- the only bug in the batch enabling local OS-level privilege escalation via a malicious file rather than sandbox escape via a web page.
- CVE-2026-17653 (use-after-free in Skia, Chromium issue #520514458) published in NVD as Critical severity.
- CVE-2026-17652 (use-after-free in Views, Chromium issue #519262990) published in NVD as Critical severity.
- CVE-2026-17651 (insufficient validation in Dawn/WebGPU on Android, Chromium issue #517307966) published in NVD as Critical severity.
- CVE-2026-17650 (use-after-free in Compositing, Chromium issue #514442821) published in NVD as Critical severity.
Sources cited for Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security
- Google Chrome 151 Fixes 370 Security Flaws
- Chrome Releases: Stable Channel Update for Desktop (151.0.7922.71/.72)
- NVD - CVE-2026-17650 (UAF in Compositing)
- NVD - CVE-2026-17651 (Insufficient validation in Dawn, Android)
- NVD - CVE-2026-17652 (UAF in Views)
- NVD - CVE-2026-17653 (UAF in Skia)
- NVD - CVE-2026-17654 (Race in Updater, macOS)
- NVD - CVE-2026-17655 (Insufficient validation in ANGLE)
- NVD - CVE-2026-17656 (UAF in Ozone)
- Chromium Issue Tracker #514442821 (CVE-2026-17650, Compositing UAF)
- Chromium Issue Tracker #517307966 (CVE-2026-17651, Dawn/WebGPU)
- Chromium Issue Tracker #519262990 (CVE-2026-17652, Views UAF)
- Chromium Issue Tracker #520514458 (CVE-2026-17653, Skia UAF)
- Chromium Issue Tracker #522314940 (CVE-2026-17654, Updater race)
- Chromium Issue Tracker #522556145 (CVE-2026-17655, ANGLE)
Detection coverage for TL-2026-1770
As of 2026-07-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1770 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.