VORANT. Threat Intelligence Sign in Get the full feed

Chrome Patches Five Use-After-Free Flaws

routine vulnerability

Google Chrome fixed five use-after-free vulnerabilities that could allow arbitrary code execution; no in-the-wild exploitation reported.

MS-ISAC advisory 2026-082 details five use-after-free vulnerabilities in Google Chrome affecting versions prior to 151.0.7922.137/.138 (Windows/Mac) and 151.0.7922.137 (Linux). The flaws span multiple Chrome components including V8, TabStrip, Extensions, HTML, and Blink. Successful exploitation could allow an attacker to execute arbitrary code in the context of the logged-on user, potentially enabling installation of programs, data manipulation, or creation of new accounts, with impact scaled to the victim's privilege level.

There are currently no reports of these vulnerabilities being exploited in the wild. The advisory recommends standard mitigations including prompt patching, least-privilege enforcement, browser sandboxing, exploit protection features, and web-content restrictions. This is a routine browser patch advisory rather than an active threat campaign.

Mentioned in this report

Vulnerabilities CVE-2026-19556CVE-2026-19557CVE-2026-19558CVE-2026-19559CVE-2026-19560

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-082

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free