# Chrome patches dozens of RCE flaws

Published: 2026-08-07 · Severity: routine
Canonical: https://vorant.io/reports/58170284-2f40-5581-90a9-525c25e0f02b/chrome-patches-dozens-of-rce-flaws

> Google Chrome released updates fixing over 30 vulnerabilities, several allowing arbitrary code execution, though none are known to be exploited yet.

CIS/MS-ISAC issued an advisory covering a large batch of vulnerabilities in Google Chrome versions prior to 151.0.7922.108/.109, affecting Windows, Mac, and Linux. The flaws span multiple Chrome components including WebGL, V8, Skia, GPU, Media, Views, and Extensions, with root causes ranging from use-after-free and heap buffer overflow to out-of-bounds write and integer overflow bugs. The most severe of these could allow arbitrary code execution in the context of the logged-on user, potentially enabling an attacker to install programs, manipulate data, or create new accounts depending on user privileges.

At the time of publication, there were no reports of active exploitation in the wild. The advisory maps the exploitation pathway to the Drive-By Compromise technique under the Initial Access tactic, indicating that a user visiting a malicious or compromised webpage could trigger exploitation without further interaction. Given the breadth of the patch set, organizations are urged to prioritize testing and deployment of the update across managed browser fleets.

Recommended mitigations focus on standard patch management and browser hardening practices: automated patch deployment, least-privilege account configurations, exploit protection features (DEP, WDEG, SIP/Gatekeeper), DNS and URL filtering, and user awareness training against phishing and malicious links. No specific threat actor, malware family, or campaign is associated with these vulnerabilities in this advisory.

## Mentioned in this report

- Vulnerabilities: CVE-2026-19137, CVE-2026-19138, CVE-2026-19139, CVE-2026-19140, CVE-2026-19141, CVE-2026-19142, CVE-2026-19143, CVE-2026-19144, CVE-2026-19145, CVE-2026-19146, CVE-2026-19147, CVE-2026-19148, CVE-2026-19149, CVE-2026-19150, CVE-2026-19151, CVE-2026-19152, CVE-2026-19153, CVE-2026-19154, CVE-2026-19155, CVE-2026-19156, CVE-2026-19157, CVE-2026-19158, CVE-2026-19159, CVE-2026-19160, CVE-2026-19161, CVE-2026-19162, CVE-2026-19163, CVE-2026-19164, CVE-2026-19165, CVE-2026-19166, CVE-2026-19167, CVE-2026-19168, CVE-2026-19169, CVE-2026-19170, CVE-2026-19171, CVE-2026-19172, CVE-2026-19173, CVE-2026-19174, CVE-2026-19175, CVE-2026-19176

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-078

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/58170284-2f40-5581-90a9-525c25e0f02b/chrome-patches-dozens-of-rce-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
