# Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security Flaws Including 7 Critical Sandbox-Escape / Local-Privilege-Escalation Bugs (CVE-2026-17650 – CVE-2026-17656)

> Google's July 29-30, 2026 Chrome 151 stable channel update (151.0.7922.71/.72 Windows/macOS, 151.0.7922.71 Linux) fixes 370 security issues -- 7 critical, 71 high, 170 medium, 122 low. All 7 critical bugs are confirmed via NVD: four use-after-free flaws (Compositing, Views, Skia, Ozone) and two insufficient-input-validation flaws (Dawn/WebGPU on Android, ANGLE) that enable sandbox escape once a renderer process is already compromised via a crafted HTML page, plus a race condition in the Chrome Updater on macOS enabling local OS-level privilege escalation via a malicious file. No CVE in this batch appears in the CISA KEV catalog and no public PoC or in-the-wild exploitation has been reported.

- **Published:** 2026-07-30T00:00:00Z
- **Last reviewed:** 2026-07-30T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1770
- **ID:** TL-2026-1770
- **Severity:** CRITICAL
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 29 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-17650, CVE-2026-17651, CVE-2026-17652, CVE-2026-17653, CVE-2026-17654, CVE-2026-17655, CVE-2026-17656

## Description

On July 29-30, 2026, Google published the Chrome 151 stable channel update (chromereleases.googleblog.com), raising the desktop build to 151.0.7922.71/.72 on Windows and macOS and 151.0.7922.71 on Linux, and fixing 370 total security issues (7 critical / 71 high / 170 medium / 122 low per the GBHackers writeup that seeded this threat). The 7 critical issues were independently confirmed against NVD, each carrying a Chromium 'Critical' severity rating and a linked issues.chromium.org tracker entry (still access-restricted, consistent with Google's standard embargo until a majority of users have updated):

- CVE-2026-17650 -- Use-after-free in Compositing (CWE-416): a remote attacker who has already compromised the renderer process can potentially achieve sandbox escape via a crafted HTML page.
- CVE-2026-17651 -- Insufficient validation of untrusted input in Dawn (Chrome's WebGPU implementation) on Android (CWE-20): a remote attacker can potentially perform sandbox escape via a crafted HTML page. This is the only one of the seven scoped specifically to Android.
- CVE-2026-17652 -- Use-after-free in Views, Chromium's cross-platform UI toolkit (CWE-416): same renderer-compromise-to-sandbox-escape pattern as 17650.
- CVE-2026-17653 -- Use-after-free in Skia, Chromium's 2D graphics rendering library (CWE-416): same pattern.
- CVE-2026-17654 -- Race condition in the Chrome Updater on macOS (CWE-362): a LOCAL attacker can perform OS-level privilege escalation via a malicious file. This is the only one of the seven that does not require a prior renderer compromise and does not rely on the 'crafted HTML page' vector -- it is a local, file-based TOCTOU-class updater flaw.
- CVE-2026-17655 -- Insufficient validation of untrusted input in ANGLE, the graphics translation layer Chrome uses to map WebGL/GPU calls to native graphics APIs (CWE-20): sandbox escape via crafted HTML page.
- CVE-2026-17656 -- Use-after-free in Ozone, Chromium's Linux/embedded display-abstraction layer (CWE-416): sandbox escape via crafted HTML page.

Six of the seven (all except the Updater race condition) follow an identical exploit-chain shape documented verbatim in each NVD record: the attacker must first achieve arbitrary code execution inside the sandboxed renderer process (typically via a separate, unpatched renderer-side memory-corruption bug or a scripting-engine flaw, not part of this disclosure), and then trigger the UAF/validation flaw in a lower-privileged-but-still-sandboxed component (Compositing, Views, Skia, Ozone, Dawn, ANGLE) to break out of the Chrome sandbox into the higher-privileged browser process -- i.e., these are second-stage sandbox-escape primitives in a multi-bug exploit chain, not standalone remote-code-execution bugs on their own. This matches the classic Chrome exploit-chain pattern (renderer 1-day/0-day + sandbox-escape 1-day/0-day) used by commercial exploit brokers and APT-affiliated exploit developers.

Google credited a mix of external researchers and internal detection via memory-safety tooling (AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL fuzzing) for the broader 370-bug batch; the source article did not break out individual bounty amounts or named researchers for the 7 critical bugs specifically. Neither the GBHackers source article, the Chrome release blog excerpt, nor a direct CISA KEV catalog check found evidence of active exploitation or a public proof-of-concept for any of the 7 critical CVEs as of 2026-07-30. Given Chrome's dominant global browser market share, the volume of critical memory-safety fixes in a single release, and the fact 6 of 7 are sandbox-escape primitives exploitable via nothing more than a crafted web page (once chained with a renderer bug), this release warrants priority patch rollout even absent confirmed in-the-wild activity.

## MITRE ATT&CK

- T1592.002 Software
- T1587.004 Exploits
- T1588.005 Exploits
- T1189 Drive-by Compromise
- T1566.002 Spearphishing Link
- T1203 Exploitation for Client Execution
- T1204.001 Malicious Link
- T1204.002 Malicious File
- T1068 Exploitation for Privilege Escalation
- T1548 Abuse Elevation Control Mechanism
- T1211 Exploitation for Stealth
- T1588.006 Vulnerabilities
- T1608.005 Link Target
- T1059.007 JavaScript
- T1574.010 Services File Permissions Weakness
- T1082 System Information Discovery

## Sources

- [Google Chrome 151 Fixes 370 Security Flaws](https://gbhackers.com/google-chrome-151-fixes-370-security-flaws/)
- [Chrome Releases: Stable Channel Update for Desktop (151.0.7922.71/.72)](https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html)
- [NVD - CVE-2026-17650 (UAF in Compositing)](https://nvd.nist.gov/vuln/detail/CVE-2026-17650)
- [NVD - CVE-2026-17651 (Insufficient validation in Dawn, Android)](https://nvd.nist.gov/vuln/detail/CVE-2026-17651)
- [NVD - CVE-2026-17652 (UAF in Views)](https://nvd.nist.gov/vuln/detail/CVE-2026-17652)
- [NVD - CVE-2026-17653 (UAF in Skia)](https://nvd.nist.gov/vuln/detail/CVE-2026-17653)
- [NVD - CVE-2026-17654 (Race in Updater, macOS)](https://nvd.nist.gov/vuln/detail/CVE-2026-17654)
- [NVD - CVE-2026-17655 (Insufficient validation in ANGLE)](https://nvd.nist.gov/vuln/detail/CVE-2026-17655)
- [NVD - CVE-2026-17656 (UAF in Ozone)](https://nvd.nist.gov/vuln/detail/CVE-2026-17656)
- [Chromium Issue Tracker #514442821 (CVE-2026-17650, Compositing UAF)](https://issues.chromium.org/issues/514442821)
- [Chromium Issue Tracker #517307966 (CVE-2026-17651, Dawn/WebGPU)](https://issues.chromium.org/issues/517307966)
- [Chromium Issue Tracker #519262990 (CVE-2026-17652, Views UAF)](https://issues.chromium.org/issues/519262990)
- [Chromium Issue Tracker #520514458 (CVE-2026-17653, Skia UAF)](https://issues.chromium.org/issues/520514458)
- [Chromium Issue Tracker #522314940 (CVE-2026-17654, Updater race)](https://issues.chromium.org/issues/522314940)
- [Chromium Issue Tracker #522556145 (CVE-2026-17655, ANGLE)](https://issues.chromium.org/issues/522556145)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1770
