Summary

Google has released Chrome 151 with fixes for 382 security vulnerabilities across the browser’s core engine, graphics stack, extensions framework, and cross-platform components. Among the patched flaws, 15 are classified as critical and 67 as high severity, with several capable of enabling remote code execution within the renderer sandbox or full sandbox escapes.

The vulnerability types include use-after-free, type confusion, and insufficient input validation bugs. Many were discovered by Google’s internal security teams, while external researchers also contributed findings through the Chrome Vulnerability Rewards Program and received bounties.

Users running Chrome on all platforms are urged to update to version 151 immediately, as the combination of critical RCE and sandbox escape vulnerabilities represents a serious risk for drive-by exploitation.

Sources

Commentary

382 vulnerabilities in a single browser release is staggering, even by Chrome’s standards. The 15 critical flaws are the headline concern — especially the sandbox escapes, which would allow an attacker to break out of Chrome’s security boundary and execute code on the underlying system. That’s the difference between “browser tab gets owned” and “entire machine gets owned.”

Chrome’s auto-update mechanism helps, but enterprise environments that manage browser deployments centrally need to push this version aggressively. Between this and the Apple patches, it’s been a brutal week for anyone responsible for endpoint patch management.

By Allan