Chrome Patches 300+ Flaws, No Active Exploits
Google Chrome update fixes several hundred vulnerabilities, some enabling arbitrary code execution, with no known in-the-wild exploitation yet.
Google has released Chrome 151.0.7922.71/.72 (Windows/Mac) and 151.0.7922.71 (Linux) to remediate an unusually large batch of vulnerabilities—well over 300 distinct CVEs spanning use-after-free, out-of-bounds read/write, type confusion, integer overflow, and insufficient input validation issues across nearly every major Chrome subsystem including V8, ANGLE, Skia, Dawn, Media, Extensions, DevTools, Passwords, and Chrome for iOS. The most severe of these could allow an attacker to achieve arbitrary code execution in the context of the logged-on user via a drive-by compromise (T1189), potentially enabling installation of programs, data manipulation, or account creation depending on the victim's privilege level.
MS-ISAC explicitly notes there are no current reports of exploitation in the wild, and the vulnerabilities affect the full range of users—government, business, and home—at a similarly elevated risk rating in each category. Given the scale of the fix (hundreds of CVEs bundled into a single release) but the absence of confirmed active exploitation, this is a standard, high-volume patch cycle rather than an emergent threat. Organizations should prioritize timely deployment via automated patch management, enforce least-privilege configurations, and maintain standard browser-hardening controls (DNS/URL filtering, exploit protection, user training) as outlined in CIS Safeguards.
Because Chrome is deployed at massive scale across consumer and enterprise environments, any subset of these flaws being weaponized post-disclosure would carry significant reach. Defenders should treat this as a mandatory update cycle and monitor vendor/CISA channels for any change in exploitation status.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-076
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free