Threat reportVulnerabilityTL-2026-1770

Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security Flaws Including 7 Critical Sandbox-Escape / Local-Privilege-Escalation Bugs (CVE-2026-17650 – CVE-2026-17656)

criticalPATCHED

Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security (TL-2026-1770) is a critical-severity software vulnerability, first published 2026-07-30. It has no confirmed attribution, affects Google Google Chrome (Windows), references 7 CVEs (CVE-2026-17650, CVE-2026-17651, CVE-2026-17652), maps to 16 MITRE ATT&CK techniques (T1059.007, T1068, T1082), and is covered by 9 detection rules and 29 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
7Referenced vulnerabilities
Techniques
16MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
29Indicators of compromise

Key facts for TL-2026-1770

Threat ID
TL-2026-1770
Severity
CRITICAL
Status
PATCHED
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
government administration, finance, health, technology, education, critical-infrastructure, retail, general-enterprise
Target regions
global
Detection rules
9
Indicators of compromise
29

Malware and tooling in Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security

Malware and tooling: AFL, AddressSanitizer, Control Flow Integrity, MemorySanitizer, UndefinedBehaviorSanitizer, libFuzzer

How Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security works

Google's July 29-30, 2026 Chrome 151 stable channel update (151.0.7922.71/.72 Windows/macOS, 151.0.7922.71 Linux) fixes 370 security issues -- 7 critical, 71 high, 170 medium, 122 low. All 7 critical bugs are confirmed via NVD: four use-after-free flaws (Compositing, Views, Skia, Ozone) and two insufficient-input-validation flaws (Dawn/WebGPU on Android, ANGLE) that enable sandbox escape once a renderer process is already compromised via a crafted HTML page, plus a race condition in the Chrome Updater on macOS enabling local OS-level privilege escalation via a malicious file. No CVE in this batch appears in the CISA KEV catalog and no public PoC or in-the-wild exploitation has been reported.

On July 29-30, 2026, Google published the Chrome 151 stable channel update (chromereleases.googleblog.com), raising the desktop build to 151.0.7922.71/.72 on Windows and macOS and 151.0.7922.71 on Linux, and fixing 370 total security issues (7 critical / 71 high / 170 medium / 122 low per the GBHackers writeup that seeded this threat). The 7 critical issues were independently confirmed against NVD, each carrying a Chromium 'Critical' severity rating and a linked issues.chromium.org tracker entry (still access-restricted, consistent with Google's standard embargo until a majority of users have updated):

- CVE-2026-17650 -- Use-after-free in Compositing (CWE-416): a remote attacker who has already compromised the renderer process can potentially achieve sandbox escape via a crafted HTML page. - CVE-2026-17651 -- Insufficient validation of untrusted input in Dawn (Chrome's WebGPU implementation) on Android (CWE-20): a remote attacker can potentially perform sandbox escape via a crafted HTML page. This is the only one of the seven scoped specifically to Android. - CVE-2026-17652 -- Use-after-free in Views, Chromium's cross-platform UI toolkit (CWE-416): same renderer-compromise-to-sandbox-escape pattern as 17650. - CVE-2026-17653 -- Use-after-free in Skia, Chromium's 2D graphics rendering library (CWE-416): same pattern. - CVE-2026-17654 -- Race condition in the Chrome Updater on macOS (CWE-362): a LOCAL attacker can perform OS-level privilege escalation via a malicious file. This is the only one of the seven that does not require a prior renderer compromise and does not rely on the 'crafted HTML page' vector -- it is a local, file-based TOCTOU-class updater flaw. - CVE-2026-17655 -- Insufficient validation of untrusted input in ANGLE, the graphics translation layer Chrome uses to map WebGL/GPU calls to native graphics APIs (CWE-20): sandbox escape via crafted HTML page. - CVE-2026-17656 -- Use-after-free in Ozone, Chromium's Linux/embedded display-abstraction layer (CWE-416): sandbox escape via crafted HTML page.

Six of the seven (all except the Updater race condition) follow an identical exploit-chain shape documented verbatim in each NVD record: the attacker must first achieve arbitrary code execution inside the sandboxed renderer process (typically via a separate, unpatched renderer-side memory-corruption bug or a scripting-engine flaw, not part of this disclosure), and then trigger the UAF/validation flaw in a lower-privileged-but-still-sandboxed component (Compositing, Views, Skia, Ozone, Dawn, ANGLE) to break out of the Chrome sandbox into the higher-privileged browser process -- i.e., these are second-stage sandbox-escape primitives in a multi-bug exploit chain, not standalone remote-code-execution bugs on their own. This matches the classic Chrome exploit-chain pattern (renderer 1-day/0-day + sandbox-escape 1-day/0-day) used by commercial exploit brokers and APT-affiliated exploit developers.

Google credited a mix of external researchers and internal detection via memory-safety tooling (AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL fuzzing) for the broader 370-bug batch; the source article did not break out individual bounty amounts or named researchers for the 7 critical bugs specifically. Neither the GBHackers source article, the Chrome release blog excerpt, nor a direct CISA KEV catalog check found evidence of active exploitation or a public proof-of-concept for any of the 7 critical CVEs as of 2026-07-30. Given Chrome's dominant global browser market share, the volume of critical memory-safety fixes in a single release, and the fact 6 of 7 are sandbox-escape primitives exploitable via nothing more than a crafted web page (once chained with a renderer bug), this release warrants priority patch rollout even absent confirmed in-the-wild activity.

MITRE ATT&CK techniques used in TL-2026-1770

Execution

T1059.007 JavaScript; T1203 Exploitation for Client Execution; T1204.001 Malicious Link; T1204.002 Malicious File

Privilege Escalation

T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism

Discovery

T1082 System Information Discovery

Initial Access

T1189 Drive-by Compromise; T1566.002 Spearphishing Link

Defense Evasion

T1211 Exploitation for Stealth

stealth

T1574.010 Services File Permissions Weakness

Resource Development

T1587.004 Exploits; T1588.005 Exploits; T1588.006 Vulnerabilities; T1608.005 Link Target

Reconnaissance

T1592.002 Software

Affected products and versions in Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security

  • Google — Google Chrome (Windows)
    Vulnerable versions: < 151.0.7922.71
    Fixed in: 151.0.7922.71; 151.0.7922.72
  • Google — Google Chrome (macOS)
    Vulnerable versions: < 151.0.7922.71
    Fixed in: 151.0.7922.71; 151.0.7922.72
  • Google — Google Chrome (Linux)
    Vulnerable versions: < 151.0.7922.71
    Fixed in: 151.0.7922.71
  • Google — Google Chrome (Android)
    Vulnerable versions: < 151.0.7922.72
    Fixed in: 151.0.7922.72
  • Google / Chromium Project — Chromium (open-source upstream; affects all downstream Chromium-based browsers pending their own rebase)
    Vulnerable versions: < 151.0.7922.71
    Fixed in: 151.0.7922.71+

Remediation for Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security

Patches

  • Google Chrome 151.0.7922.71/.72 (Windows)
  • Google Chrome 151.0.7922.71/.72 (macOS)
  • Google Chrome 151.0.7922.71 (Linux)
  • Google Chrome 151.0.7922.72 (Android, for CVE-2026-17651)

Immediate actions

  • Update Google Chrome to 151.0.7922.71/.72 (Windows), 151.0.7922.71/.72 (macOS), or 151.0.7922.71 (Linux) via chrome://settings/help, then relaunch the browser to load the patched binary.
  • For managed/enterprise fleets, push the update via Chrome Enterprise policy (TargetVersionPrefix / auto-update) rather than waiting on end-user relaunch, given 6 of the 7 critical bugs are exploitable via nothing more than visiting a crafted web page once chained with a renderer bug.
  • macOS fleets specifically: prioritize rollout given CVE-2026-17654 is a locally-triggerable Updater race condition unique to macOS.
  • Android fleets: prioritize rollout given CVE-2026-17651 (Dawn/WebGPU) is Android-specific.

Workarounds

  • No official workaround supersedes patching. Disabling WebGPU (chrome://flags -> #enable-unsafe-webgpu / Dawn) reduces exposure to CVE-2026-17651 on Android until patched.
  • Disabling GPU/hardware compositing (chrome://flags -> #disable-gpu-compositing) offers partial mitigation for the Compositing UAF (CVE-2026-17650) but degrades rendering performance and is not a substitute for updating.

Longer-term hardening

  • Enforce mandatory automatic browser updates via Chrome Enterprise / Chrome Browser Cloud Management so critical patches land within days, not weeks.
  • Maintain Site Isolation and renderer-sandbox hardening as defense-in-depth against the class of UAF/sandbox-escape bugs recurring across Compositing, Views, Skia, Ozone, Dawn, and ANGLE.
  • Track the CVE-2026-17650 through CVE-2026-17656 range against fleet telemetry (chrome://version reporting) to confirm 100% patch compliance, and re-check CISA KEV periodically in case any of the seven are later added following in-the-wild observation.

CVEs associated with Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security

CVE-2026-17650, CVE-2026-17651, CVE-2026-17652, CVE-2026-17653, CVE-2026-17654, CVE-2026-17655, CVE-2026-17656

Weaknesses (CWE) in Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security

CWE-416, CWE-20, CWE-362

Timeline of Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security

  • Google publishes the Chrome 151 Stable Channel Update for Desktop blog post, raising the build to 151.0.7922.71/.72 (Windows/macOS) and 151.0.7922.71 (Linux) and fixing 370 total security issues.
  • CISA Known Exploited Vulnerabilities catalog checked directly; none of CVE-2026-17650 through CVE-2026-17656 present, confirming no CISA-confirmed active exploitation as of this analysis.
  • TL-Intel-Harness ingests the GBHackers article via the RSS hunt pipeline and opens threat TL-2026-1770.
  • GBHackers publishes "Google Chrome 151 Fixes 370 Security Flaws", summarizing all severity tiers and the 7 critical component-level bugs.
  • CVE-2026-17656 (use-after-free in Ozone, Chromium issue #523725277) published in NVD as Critical severity.
  • CVE-2026-17655 (insufficient validation in ANGLE, Chromium issue #522556145) published in NVD as Critical severity.
  • CVE-2026-17654 (race condition in Chrome Updater on macOS, Chromium issue #522314940) published in NVD as Critical severity -- the only bug in the batch enabling local OS-level privilege escalation via a malicious file rather than sandbox escape via a web page.
  • CVE-2026-17653 (use-after-free in Skia, Chromium issue #520514458) published in NVD as Critical severity.
  • CVE-2026-17652 (use-after-free in Views, Chromium issue #519262990) published in NVD as Critical severity.
  • CVE-2026-17651 (insufficient validation in Dawn/WebGPU on Android, Chromium issue #517307966) published in NVD as Critical severity.
  • CVE-2026-17650 (use-after-free in Compositing, Chromium issue #514442821) published in NVD as Critical severity.

Sources cited for Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security

Detection coverage for TL-2026-1770

As of 2026-07-30, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1770 across Splunk SPL, Microsoft KQL and Sigma, covering 29 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
29 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats