# Chrome Patches Five Use-After-Free Flaws

Published: 2026-08-12 · Severity: routine
Canonical: https://vorant.io/reports/b0dfeee6-65b4-5396-9c6b-c4c6bdfb3f2e/chrome-patches-five-use-after-free-flaws

> Google Chrome fixed five use-after-free vulnerabilities that could allow arbitrary code execution; no in-the-wild exploitation reported.

MS-ISAC advisory 2026-082 details five use-after-free vulnerabilities in Google Chrome affecting versions prior to 151.0.7922.137/.138 (Windows/Mac) and 151.0.7922.137 (Linux). The flaws span multiple Chrome components including V8, TabStrip, Extensions, HTML, and Blink. Successful exploitation could allow an attacker to execute arbitrary code in the context of the logged-on user, potentially enabling installation of programs, data manipulation, or creation of new accounts, with impact scaled to the victim's privilege level.

There are currently no reports of these vulnerabilities being exploited in the wild. The advisory recommends standard mitigations including prompt patching, least-privilege enforcement, browser sandboxing, exploit protection features, and web-content restrictions. This is a routine browser patch advisory rather than an active threat campaign.

## Mentioned in this report

- Vulnerabilities: CVE-2026-19556, CVE-2026-19557, CVE-2026-19558, CVE-2026-19559, CVE-2026-19560

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-082

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/b0dfeee6-65b4-5396-9c6b-c4c6bdfb3f2e/chrome-patches-five-use-after-free-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
