Chrome Patches Five Use-After-Free Flaws
Google Chrome fixed five use-after-free vulnerabilities that could allow arbitrary code execution; no in-the-wild exploitation reported.
MS-ISAC advisory 2026-082 details five use-after-free vulnerabilities in Google Chrome affecting versions prior to 151.0.7922.137/.138 (Windows/Mac) and 151.0.7922.137 (Linux). The flaws span multiple Chrome components including V8, TabStrip, Extensions, HTML, and Blink. Successful exploitation could allow an attacker to execute arbitrary code in the context of the logged-on user, potentially enabling installation of programs, data manipulation, or creation of new accounts, with impact scaled to the victim's privilege level.
There are currently no reports of these vulnerabilities being exploited in the wild. The advisory recommends standard mitigations including prompt patching, least-privilege enforcement, browser sandboxing, exploit protection features, and web-content restrictions. This is a routine browser patch advisory rather than an active threat campaign.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-082
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free