Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
MS-ISAC ADVISORY NUMBER:
2026-076DATE(S) ISSUED:
07/30/2026OVERVIEW:
Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
THREAT INTELLIGENCE:
There are currently no reports of these vulnerabilities being exploited in the wild.
SYSTEMS AFFECTED:
- Chrome prior to 151.0.7922.71/.72 for Windows and Mac
- Chrome prior to 151.0.7922.71 for Linux
RISK:
Government:
Businesses:
Home Users:
TECHNICAL SUMMARY:
Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Details of these vulnerabilities are as follows:
Tactic: Initial Access (TA0001):
Technique: Drive-By Compromise (T1189):
- Use after free in Compositing (CVE-2026-17650)
- Insufficient validation of untrusted input in Dawn (CVE-2026-17651, CVE-2026-17867)
- Use after free in Views (CVE-2026-17652, CVE-2026-17670, CVE-2026-17699, CVE-2026-17752, CVE-2026-17894)
- Use after free in Skia (CVE-2026-17653)
- Race in Updater (CVE-2026-17654, CVE-2026-17993)
- Insufficient validation of untrusted input in ANGLE (CVE-2026-17655, CVE-2026-17671, CVE-2026-17847)
- Use after free in Ozone (CVE-2026-17656)
- Use after free in Navigation (CVE-2026-17657)
- Use after free in V8 (CVE-2026-17658, CVE-2026-17665, CVE-2026-17729, CVE-2026-17807, CVE-2026-17836, CVE-2026-17920)
- Inappropriate implementation in SiteIsolation (CVE-2026-17659)
- Insufficient validation of untrusted input in Network (CVE-2026-17660)
- Use after free in Loader (CVE-2026-17661)
- Insufficient policy enforcement in Prefetch (CVE-2026-17662)
- Insufficient validation of untrusted input in GPU (CVE-2026-17663)
- Insufficient validation of untrusted input in Loader (CVE-2026-17664)
- Cryptographic Flaw in Enterprise (CVE-2026-17666)
- Uninitialized Use in ANGLE (CVE-2026-17667, CVE-2026-17668, CVE-2026-17689, CVE-2026-17714, CVE-2026-17740, CVE-2026-17785, CVE-2026-17790)
- Inappropriate implementation in Chrome for iOS (CVE-2026-17669, CVE-2026-17762, CVE-2026-17822, CVE-2026-17826, CVE-2026-17828, CVE-2026-17830, CVE-2026-17835, CVE-2026-17839, CVE-2026-17842, CVE-2026-17849, CVE-2026-17874, CVE-2026-17912, CVE-2026-17913, CVE-2026-17941, CVE-2026-17944, CVE-2026-17960, CVE-2026-17972, CVE-2026-18003, CVE-2026-18011, CVE-2026-18013)
- Insufficient validation of untrusted input in Chromecast (CVE-2026-17672)
- Integer overflow in QUIC (CVE-2026-17673)
- Inappropriate implementation in HTML (CVE-2026-17674)
- Out of bounds write in ANGLE (CVE-2026-17675, CVE-2026-17691, CVE-2026-17721)
- Inappropriate implementation in ANGLE (CVE-2026-17676, CVE-2026-17677, CVE-2026-17683, CVE-2026-17695)
- Out of bounds read in ANGLE (CVE-2026-17678, CVE-2026-17701)
- Insufficient validation of untrusted input in Print Preview (CVE-2026-17679)
- Heap buffer overflow in Color (CVE-2026-17680)
- Insufficient validation of untrusted input in Web Authentication (CVE-2026-17681)
- Integer overflow in ANGLE (CVE-2026-17682, CVE-2026-17717)
- Insufficient validation of untrusted input in Chrome for iOS (CVE-2026-17684, CVE-2026-17761, CVE-2026-17789, CVE-2026-17814)
- Use after free in Autofill (CVE-2026-17685)
- Insufficient validation of untrusted input in Passwords (CVE-2026-17686, CVE-2026-17831, CVE-2026-17970, CVE-2026-18009)
- Type Confusion in ANGLE (CVE-2026-17687, CVE-2026-17697)
- Use after free in Input (CVE-2026-17688, CVE-2026-17719)
- Insufficient validation of untrusted input in PDF (CVE-2026-17690)
- Use after free in DataTransfer (CVE-2026-17692, CVE-2026-17932)
- Inappropriate implementation in FileSystem (CVE-2026-17693)
- Use after free in DOM (CVE-2026-17694)
- Side-channel information leakage in Media (CVE-2026-17696, CVE-2026-18019)
- Insufficient validation of untrusted input in UI (CVE-2026-17698)
- Insufficient validation of untrusted input in Actor (CVE-2026-17700)
- Inappropriate implementation in Skia (CVE-2026-17702)
- Policy bypass in Chrome for iOS (CVE-2026-17703, CVE-2026-17917)
- Use after free in ANGLE (CVE-2026-17704, CVE-2026-17718, CVE-2026-17750, CVE-2026-17811, CVE-2026-17832, CVE-2026-17891)
- Integer overflow in libxml (CVE-2026-17705)
- Insufficient validation of untrusted input in Media (CVE-2026-17706)
- Uninitialized Use in Media (CVE-2026-17707)
- Use after free in Audio (CVE-2026-17708, CVE-2026-17784)
- Race in Downloads (CVE-2026-17709, CVE-2026-17711)
- Inappropriate implementation in MHTML (CVE-2026-17710)
- Race in Skia (CVE-2026-17712)
- Insufficient validation of untrusted input in Accessibility (CVE-2026-17713)
- Inappropriate implementation in Passwords (CVE-2026-17715, CVE-2026-17833, CVE-2026-17834, CVE-2026-17871, CVE-2026-17939, CVE-2026-17969, CVE-2026-17997, CVE-2026-18010)
- Use after free in Updater (CVE-2026-17716)
- Insufficient policy enforcement in Passwords (CVE-2026-17720, CVE-2026-17825, CVE-2026-17829)
- Object lifecycle issue in WebView (CVE-2026-17722)
- Use after free in Media (CVE-2026-17723, CVE-2026-17804)
- Race in Chrome for iOS (CVE-2026-17724, CVE-2026-17841)
- Type Confusion in V8 (CVE-2026-17725, CVE-2026-17948, CVE-2026-17989)
- Integer overflow in WebGL (CVE-2026-17726)
- Out of bounds write in WebGL (CVE-2026-17727)
- Inappropriate implementation in Extensions (CVE-2026-17728, CVE-2026-17748, CVE-2026-17781)
- Heap buffer overflow in Dawn (CVE-2026-17758)
- Inappropriate implementation in SVG (CVE-2026-17732, CVE-2026-17963)
- Side-channel information leakage in Autofill (CVE-2026-17730, CVE-2026-17851)
- Inappropriate implementation in Autofill (CVE-2026-17731, CVE-2026-17734, CVE-2026-17753, CVE-2026-17777, CVE-2026-17879, CVE-2026-17880)
- Inappropriate implementation in QUIC (CVE-2026-17733)
- Insufficient validation of untrusted input in BFCache (CVE-2026-17735)
- Insufficient validation of untrusted input in WebView (CVE-2026-17736, CVE-2026-17741, CVE-2026-17767)
- Use after free in Bluetooth (CVE-2026-17737)
- Insufficient validation of untrusted input in Payments (CVE-2026-17738, CVE-2026-17747, CVE-2026-17791, CVE-2026-17955)
- Insufficient policy enforcement in Extensions (CVE-2026-17739, CVE-2026-17821)
- Insufficient policy enforcement in Payments (CVE-2026-17742)
- Insufficient policy enforcement in ControlledFrame (CVE-2026-17743)
- Inappropriate implementation in File Input (CVE-2026-17744)
- Out of bounds read in Skia (CVE-2026-17745)
- Use after free in GPU (CVE-2026-17746)
- Insufficient validation of untrusted input in Extensions (CVE-2026-17749, CVE-2026-17806, CVE-2026-17809, CVE-2026-17930)
- Inappropriate implementation in AdFilter (CVE-2026-17751)
- Inappropriate implementation in Blink (CVE-2026-17754, CVE-2026-17788, CVE-2026-17962, CVE-2026-17981)
- Incorrect security UI in Extensions (CVE-2026-17755, CVE-2026-17998)
- Insufficient policy enforcement in Presentation (CVE-2026-17756)
- Uninitialized Use in Skia (CVE-2026-17757, CVE-2026-17771, CVE-2026-17992)
- Uninitialized Use in Codecs (CVE-2026-17759)
- Side-channel information leakage in NoStatePrefetch (CVE-2026-17760)
- Inappropriate implementation in GPU (CVE-2026-17763)
- Inappropriate implementation in FedCM (CVE-2026-17764)
- Inappropriate implementation in WebProtect (CVE-2026-17765)
- Insufficient validation of untrusted input in Clipboard (CVE-2026-17766)
- Insufficient validation of untrusted input in WebSockets (CVE-2026-17768)
- Insufficient validation of untrusted input in Cast (CVE-2026-17769, CVE-2026-17773, CVE-2026-17844, CVE-2026-17870, CVE-2026-17982)
- Out of bounds read in Media (CVE-2026-17770)
- Out of bounds read in WebGL (CVE-2026-17772)
- Insufficient validation of untrusted input in Variations (CVE-2026-17774)
- Inappropriate implementation in PresentationAPI (CVE-2026-17775)
- Policy bypass in Receiver (CVE-2026-17776)
- Use after free in Extensions (CVE-2026-17778)
- Inappropriate implementation in Site Isolation (CVE-2026-17779)
- Inappropriate implementation in Isolated Web Apps (CVE-2026-17780)
- Incorrect security UI in Chrome for iOS (CVE-2026-17782, CVE-2026-17838, CVE-2026-17965)
- Inappropriate implementation in Loader (CVE-2026-17783)
- Insufficient validation of untrusted input in DevTools (CVE-2026-17786, CVE-2026-17837, CVE-2026-17890, CVE-2026-17926, CVE-2026-17929, CVE-2026-17934, CVE-2026-18014)
- Inappropriate implementation in DevTools (CVE-2026-17787, CVE-2026-17853, CVE-2026-17931, CVE-2026-17936, CVE-2026-17937)
- Inappropriate implementation in Credential Management (CVE-2026-17792)
- Inappropriate implementation in Messages (CVE-2026-17793)
- Insufficient validation of untrusted input in Mobile (CVE-2026-17794, CVE-2026-17860)
- Insufficient validation of untrusted input in GetUserMedia (CVE-2026-17795)
- Side-channel information leakage in WebXR (CVE-2026-17796)
- Inappropriate implementation in CSS (CVE-2026-17797, CVE-2026-17827, CVE-2026-17843, CVE-2026-17845, CVE-2026-17878)
- Inappropriate implementation in Cast (CVE-2026-17798, CVE-2026-17925)
- Insufficient validation of untrusted input in Safe Browsing (CVE-2026-17799)
- Side-channel information leakage in MediaRecording (CVE-2026-17800)
- Out of bounds memory access in ANGLE (CVE-2026-17801)
- Side-channel information leakage in GPU (CVE-2026-17802)
- Insufficient validation of untrusted input in Save to Drive (CVE-2026-17803)
- Insufficient policy enforcement in Glic (CVE-2026-17805)
- Uninitialized Use in WebGL (CVE-2026-17808)
- Uninitialized Use in Dawn (CVE-2026-17810, CVE-2026-17946)
- Inappropriate implementation in DigitalCredentials (CVE-2026-17812)
- Insufficient policy enforcement in Chrome for iOS (CVE-2026-17813, CVE-2026-17873, CVE-2026-18016)
- Insufficient policy enforcement in GuestView (CVE-2026-17815)
- Inappropriate implementation in Speech (CVE-2026-17816)
- Inappropriate implementation in ReportingAndNEL (CVE-2026-17817)
- Inappropriate implementation in Network (CVE-2026-17818, CVE-2026-17856, CVE-2026-17857, CVE-2026-17959)
- Inappropriate implementation in WebAppInstalls (CVE-2026-17819)
- Insufficient policy enforcement in Autofill (CVE-2026-17820)
- Insufficient policy enforcement in WebXR (CVE-2026-17823)
- Insufficient policy enforcement in ServiceWorker (CVE-2026-17824)
- Incorrect security UI in Passwords (CVE-2026-17840)
- Inappropriate implementation in Media (CVE-2026-17846, CVE-2026-17994)
- Insufficient validation of untrusted input in Codecs (CVE-2026-17848)
- Inappropriate implementation in Permissions (CVE-2026-17850)
- Inappropriate implementation in Media Router (CVE-2026-17852)
- Insufficient policy enforcement in WebMCP (CVE-2026-17854)
- Race in DevTools (CVE-2026-17855)
- Uninitialized Use in WebNN (CVE-2026-17858)
- Side-channel information leakage in Favicons (CVE-2026-17859)
- Insufficient validation of untrusted input in Updater (CVE-2026-17861, CVE-2026-17893)
- Use after free in Tracing (CVE-2026-17862)
- Inappropriate implementation in Browser (CVE-2026-17863, CVE-2026-17984, CVE-2026-17996)
- Inappropriate implementation in Updater (CVE-2026-17864, CVE-2026-18018)
- Inappropriate implementation in Crypto (CVE-2026-17865)
- Type Confusion in Tab (CVE-2026-17866)
- Insufficient policy enforcement in USB (CVE-2026-17868, CVE-2026-18000)
- Out of bounds read in WebXR (CVE-2026-17869)
- Cryptographic Flaw in WebAppInstalls (CVE-2026-17872)
- Use after free in PDFium (CVE-2026-17875, CVE-2026-18012)
- Inappropriate implementation in Payments (CVE-2026-17876)
- Inappropriate implementation in Chromoting (CVE-2026-17877)
- Use after free in WebXR (CVE-2026-17881)
- Policy bypass in Extensions (CVE-2026-17882, CVE-2026-17976)
- Inappropriate implementation in Headless (CVE-2026-17883)
- Object lifecycle issue in WebRTC (CVE-2026-17884)
- Inappropriate implementation in Paint (CVE-2026-17885)
- Use after free in Enterprise (CVE-2026-17886)
- Use after free in TabStrip (CVE-2026-17887)
- Insufficient validation of untrusted input in WebUI (CVE-2026-17888)
- Uninitialized Use in WebXR (CVE-2026-17889, CVE-2026-17968)
- Inappropriate implementation in WebXR (CVE-2026-17892, CVE-2026-18005)
- Inappropriate implementation in DataTransfer (CVE-2026-17895, CVE-2026-17928)
- Use after free in DevTools (CVE-2026-17896, CVE-2026-17898)
- Inappropriate implementation in ORB (CVE-2026-17897)
- Insufficient policy enforcement in DevTools (CVE-2026-17899, CVE-2026-17927, CVE-2026-17974)
- Inappropriate implementation in Enterprise (CVE-2026-17900, CVE-2026-17922)
- Inappropriate implementation in Sharing (CVE-2026-17901)
- Inappropriate implementation in Editing (CVE-2026-17902)
- Insufficient policy enforcement in Chromecast (CVE-2026-17903)
- Insufficient policy enforcement in NFC (CVE-2026-17904, CVE-2026-17910)
- Inappropriate implementation in SurfaceCapture (CVE-2026-17905)
- Insufficient validation of untrusted input in Bluetooth (CVE-2026-17906)
- Side-channel information leakage in Network (CVE-2026-17907)
- Insufficient validation of untrusted input in Printing (CVE-2026-17908)
- Insufficient validation of untrusted input in Isolated Web Apps (CVE-2026-17909)
- Insufficient policy enforcement in SVG (CVE-2026-17911)
- Side-channel information leakage in Skia (CVE-2026-17914)
- Inappropriate implementation in WebView (CVE-2026-17915)
- Insufficient policy enforcement in Settings (CVE-2026-17916)
- Use after free in Sync (CVE-2026-17918)
- Insufficient policy enforcement in Enterprise (CVE-2026-17919)
- Insufficient validation of untrusted input in Navigation (CVE-2026-17921, CVE-2026-17988)
- Policy bypass in Enterprise (CVE-2026-17923)
- Use after free in DNS (CVE-2026-17924)
- Inappropriate implementation in DOMStorage (CVE-2026-17933)
- Heap buffer overflow in Codecs (CVE-2026-17935)
- Inappropriate implementation in FullScreen (CVE-2026-17938)
- Insufficient validation of untrusted input in Picture-in-Picture (CVE-2026-17940)
- Side-channel information leakage in SVG (CVE-2026-17942)
- Inappropriate implementation in Parser (CVE-2026-17943)
- Inappropriate implementation in Navigation (CVE-2026-17945)
- Use after free in WebSockets (CVE-2026-17947)
- Uninitialized Use in GPU (CVE-2026-17949)
- Policy bypass in Safebrowsing (CVE-2026-17950)
- Heap buffer overflow in WebRTC (CVE-2026-17951)
- Inappropriate implementation in V8 (CVE-2026-17952)
- Insufficient policy enforcement in WebView (CVE-2026-17953)
- Policy bypass in MHTML (CVE-2026-17954)
- Inappropriate implementation in Scheduling (CVE-2026-17956)
- Inappropriate implementation in CORS (CVE-2026-17957)
- Inappropriate implementation in Views (CVE-2026-17958, CVE-2026-17966, CVE-2026-17973)
- Inappropriate implementation in Session (CVE-2026-17961)
- Incorrect security UI in UI (CVE-2026-17964)
- Use after free in Chrome for iOS (CVE-2026-17967)
- Inappropriate implementation in Frame (CVE-2026-17971)
- Inappropriate implementation in IME (CVE-2026-17975)
- Policy bypass in CSS (CVE-2026-17977)
- Side-channel information leakage in WebCodecs (CVE-2026-17978)
- Race in V8 (CVE-2026-17979)
- Inappropriate implementation in UI (CVE-2026-17980)
- Incorrect security UI in Global Media Controls (CVE-2026-17983)
- Insufficient policy enforcement in Speech (CVE-2026-17985, CVE-2026-18004)
- Insufficient policy enforcement in Bluetooth (CVE-2026-17986)
- Insufficient validation of untrusted input in Notifications (CVE-2026-17987)
- Insufficient validation of untrusted input in WebAuthn (CVE-2026-17990)
- Insufficient validation of untrusted input in AI (CVE-2026-17991)
- Out of bounds read in Dawn (CVE-2026-17995)
- Incorrect security UI in PictureInPicture (CVE-2026-17999)
- Inappropriate implementation in WebGL (CVE-2026-18001)
- Insufficient validation of untrusted input in Google Lens (CVE-2026-18002)
- Inappropriate implementation in Google Lens (CVE-2026-18006)
- Inappropriate implementation in Input (CVE-2026-18007)
- Inappropriate implementation in Settings (CVE-2026-18008)
- Inappropriate implementation in Tint (CVE-2026-18015)
- Use after free in Dawn (CVE-2026-18017)
Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than those who operate with administrative user rights.
RECOMMENDATIONS:
We recommend the following actions be taken:
- Apply appropriate updates provided by Google to vulnerable systems immediately after appropriate testing. (M1051: Update Software)
- Safeguard 7.1: Establish and Maintain a Vulnerability Management Process: Establish and maintain a documented vulnerability management process for enterprise assets. Review and update documentation annually, or when significant enterprise changes occur that could impact this Safeguard.
- Safeguard 7.4: Perform Automated Application Patch Management: Perform application updates on enterprise assets through automated patch management on a monthly, or more frequent, basis.
- Safeguard 7.7: Remediate Detected Vulnerabilities: Remediate detected vulnerabilities in software through processes and tooling on a monthly, or more frequent, basis, based on the remediation process.
- Safeguard 9.1: Ensure Use of Only Fully Supported Browsers and Email Clients: Ensure only fully supported browsers and email clients are allowed to execute in the enterprise, only using the latest version of browsers and email clients provided through the vendor.
- Apply the Principle of Least Privilege to all systems and services. Run all software as a non-privileged user (one without administrative privileges) to diminish the effects of a successful attack. (M1026: Privileged Account Management)
- Safeguard 4.7: Manage Default Accounts on Enterprise Assets and Software: Manage default accounts on enterprise assets and software, such as root, administrator, and other pre-configured vendor accounts. Example implementations can include: disabling default accounts or making them unusable.
- Safeguard 5.4: Restrict Administrator Privileges to Dedicated Administrator Accounts: Restrict administrator privileges to dedicated administrator accounts on enterprise assets. Conduct general computing activities, such as internet browsing, email, and productivity suite use, from the user’s primary, non-privileged account.
- Restrict execution of code to a virtual environment on or in transit to an endpoint system. (M1048: Application Isolation and Sandboxing)
- Use capabilities to detect and block conditions that may lead to or be indicative of a software exploit occurring. (M1050: Exploit Protection)
- Safeguard 10.5: Enable Anti-Exploitation Features: Enable anti-exploitation features on enterprise assets and software, where possible, such as Microsoft® Data Execution Prevention (DEP), Windows® Defender Exploit Guard (WDEG), or Apple® System Integrity Protection (SIP) and Gatekeeper™.
- Restrict use of certain websites, block downloads/attachments, block Javascript, restrict browser extensions, etc. (M1021: Restrict Web-Based Content)
- Safeguard 9.2: Use DNS Filtering Services: Use DNS filtering services on all enterprise assets to block access to known malicious domains.
- Safeguard 9.3: Maintain and Enforce Network-Based URL Filters: Enforce and update network-based URL filters to limit an enterprise asset from connecting to potentially malicious or unapproved websites. Example implementations include category-based filtering, reputation-based filtering, or through the use of block lists. Enforce filters for all enterprise assets.
- Safeguard 9.6: Block Unnecessary File Types: Block unnecessary file types attempting to enter the enterprise’s email gateway.
- Inform and educate users regarding the threats posed by hypertext links contained in emails or attachments especially from un-trusted sources. Remind users not to visit un-trusted websites or follow links provided by unknown or un-trusted sources. (M1017: User Training)
- Safeguard 14.1: Establish and Maintain a Security Awareness Program: Establish and maintain a security awareness program. The purpose of a security awareness program is to educate the enterprise’s workforce on how to interact with enterprise assets and data in a secure manner. Conduct training at hire and, at a minimum, annually. Review and update content annually, or when significant enterprise changes occur that could impact this Safeguard.
- Safeguard 14.2: Train Workforce Members to Recognize Social Engineering Attacks: Train workforce members to recognize social engineering attacks, such as phishing, pre-texting, and tailgating.