Last updated: 31 Jul 26 12:19:50 (UTC)

Chrome 151.0.7922.71/.72 CVE Report


date: 2026-07-31
source_url: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html
total_cves: 357
severity_counts: {"Critical": 7, "High": 69, "Medium": 161, "Low": 120}
total_bounty_pool: 58500

Chrome CVE Report

Source: https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_0887107924.html Report generated: 2026-07-31 Total CVEs: 357

Executive Summary

This release contains 357 CVEs across 4 severity levels with a total bounty pool of $58,500.

  • Critical: 7
  • High: 69
  • Medium: 161
  • Low: 120
  • Bounty-bearing: 8
  • External reporters: 8

Vulnerability Type Breakdown

Type Count % of Total
Inappropriate Implementation 123 34.5%
Insufficient Input Validation 68 19.0%
Use After Free 48 13.4%
Insufficient Policy/Data Validation 31 8.7%
Uninitialized Use 19 5.3%
Side-Channel Leak 13 3.6%
Out of Bounds 11 3.1%
Race Condition 9 2.5%
Policy Bypass 9 2.5%
Incorrect Security UI 9 2.5%
Type Confusion 5 1.4%
Integer Overflow 4 1.1%
Heap Buffer Overflow 4 1.1%
Other 2 0.6%
Object Lifecycle 2 0.6%

Component Area Distribution

Component Count % of Total
XR 36 10.1%
Chrome for iOS 35 9.8%
Input Handling 33 9.2%
ANGLE (Graphics) 30 8.4%
DevTools 17 4.8%
Password Manager 16 4.5%
Extensions API 14 3.9%
Media 12 3.4%
V8 (JavaScript) 9 2.5%
Autofill 9 2.5%
Views UI 8 2.2%
Skia (Graphics) 8 2.2%
WebXR 8 2.2%
Updater/Installer 7 2.0%
Dawn (WebGPU) 6 1.7%
Networking 6 1.7%
Enterprise 6 1.7%
WebView 6 1.7%
CSS 6 1.7%
GPU 5 1.4%
General UI 5 1.4%
WebGL 5 1.4%
Navigation 4 1.1%
SVG 4 1.1%
Blink (Rendering) 4 1.1%
Other (38 more) 100 28.0%

Bounty Analysis

Total bounty pool: $58,500 Bounty-bearing CVEs: 8

CVE ID Severity Description Bounty
CVE-2026-17657 High Use after free in Navigation. $36000
CVE-2026-17728 Medium Inappropriate implementation in Extensions. $10000
CVE-2026-17758 Medium Heap buffer overflow in Dawn. $5000
CVE-2026-17898 Low Use after free in DevTools. $3000
CVE-2026-17732 Medium Inappropriate implementation in SVG. $2000
CVE-2026-17658 High Use after free in V8. $1000
CVE-2026-17899 Low Insufficient policy enforcement in DevTools. $1000
CVE-2026-17729 Medium Use after free in V8. $500

External Researcher Credits

Researcher CVEs
Duc Nguyen of Calif.io in collaboration with OpenAI Codex Security CVE-2026-17658
Hyeonjun Ahn (@_deayzl) CVE-2026-17758
Lyra Rebane (rebane2001) CVE-2026-17732
Suhas S P CVE-2026-17728
Syn4pse CVE-2026-17898
asnine CVE-2026-17899
c6eed09fc8b174b0f3eebedcceb1e792 CVE-2026-17657
wang1r && lhfff CVE-2026-17729

Critical & High Severity Analysis

76 CVEs at Critical or High severity.

By vulnerability type:

  • Use After Free: 20
  • Insufficient Input Validation: 16
  • Inappropriate Implementation: 11
  • Out of Bounds: 6
  • Race Condition: 5
  • Uninitialized Use: 5
  • Integer Overflow: 4
  • Insufficient Policy/Data Validation: 2
  • Type Confusion: 2
  • Other: 1
  • Heap Buffer Overflow: 1
  • Side-Channel Leak: 1
  • Policy Bypass: 1
  • Object Lifecycle: 1

By component:

  • ANGLE (Graphics): 21
  • Input Handling: 9
  • XR: 7
  • Chrome for iOS: 4
  • Media: 4
  • Views UI: 3
  • Skia (Graphics): 3
  • Password Manager: 3
  • Updater/Installer: 2
  • V8 (JavaScript): 2

Reporting Timeline

Date CVEs Reported
2021-08-26 1
2024-10-28 1
2025-11-16 1
2026-01-17 1
2026-03-23 1
2026-03-24 1
2026-03-25 3
2026-03-26 1
2026-03-27 1
2026-03-28 2
2026-03-29 5
2026-03-30 2
2026-03-31 3
2026-04-02 4
2026-04-03 1
2026-04-07 5
2026-04-08 4
2026-04-11 6
2026-04-12 1
2026-04-13 1
2026-04-14 3
2026-04-18 1
2026-04-19 2
2026-04-20 1
2026-04-24 1
2026-04-25 3
2026-04-30 2
2026-05-08 1
2026-05-10 7
2026-05-13 1
2026-05-14 13
2026-05-15 14
2026-05-16 22
2026-05-17 11
2026-05-18 6
2026-05-19 7
2026-05-21 5
2026-05-25 4
2026-05-26 9
2026-05-27 12
2026-05-28 28
2026-05-29 21
2026-05-30 14
2026-05-31 1
2026-06-01 4
2026-06-02 7
2026-06-03 9
2026-06-04 17
2026-06-05 15
2026-06-06 2
2026-06-07 1
2026-06-08 4
2026-06-09 11
2026-06-10 16
2026-06-11 6
2026-06-12 4
2026-06-13 9
2026-06-14 8
2026-06-15 1
2026-06-16 2
2026-06-17 3
2026-06-18 1
2026-06-19 1
2026-06-30 1
2026-07-01 1

Methodology Notes

  • Structured CVE data extracted via unjam --cve.
  • Vulnerability types and component areas classified from CVE description text.
  • Bounty amounts from the bounty field in unjam output.
  • External researchers identified from the reporter field (non-Google, non-anonymous).