Google Releases Chrome 151 Fixing 41 Vulnerabilities Including Six Critical Flaws
Google has released Chrome 151 containing fixes for 41 security vulnerabilities, including six critical flaws that can trigger memory corruption, browser crashes, and potential remote code execution on victim systems.
The new versions 151.0.7922.108 and 151.0.7922.109 are being distributed to Windows and macOS users, while Linux receives version 151.0.7922.108. Deployment occurs gradually across the user base.
Among the most severe issues are two use-after-free vulnerabilities in WebGL, recorded as CVE-2026-19137 and CVE-2026-19170. This class of flaw occurs when the browser continues to reference a memory region after it has already been freed, potentially allowing attackers to manipulate program behavior.
Other critical errors impact the Aura, Skia, and Views components, identified as CVE-2026-19149, CVE-2026-19154, and CVE-2026-19172. An additional critical issue, CVE-2026-19157, involves an out-of-bounds write in ANGLE.
In exploitation scenarios, a specially crafted webpage can attempt to trigger these flaws while the browser processes web content. The actual impact depends on the specific vulnerability and the security protections present in the underlying operating system.
Google has temporarily restricted technical details and proof-of-concept code for some of the flaws, a standard measure to reduce exposure while the update reaches the majority of users.
Users should open Chrome settings, navigate to Help, and select About Google Chrome to verify and install the update. Enterprises are encouraged to prioritize deployment of Chrome 151 across Windows, macOS, and Linux environments.
Related articles
ServiceNow Discloses Three CVSS 10.0 Vulnerabilities Allowing Unauthenticated Remote Code Execution and SQL Injection
ServiceNow has released security updates addressing four vulnerabilities in its AI platform, including three rated CVSS 10.0. The flaws enable unauthenticated attackers to achieve remote code execution, privilege escalation, and arbitrary SQL execution against core ITSM systems used by large enterprises worldwide. Affected components include the GraphQL Composite Data API, system configuration image upload processor, and dynamic schema ORDER BY handling. ServiceNow states it has patched hosted instances and provided hotfixes for self-hosted customers running Xanadu, Yokohama, Zurich, and Australia branches. This follows a July disclosure of a related sandbox escape tracked as CVE-2026-6875 that showed signs of in-the-wild exploitation. No public exploits or confirmed active attacks have been observed for the new issues yet, but the extremely low attack complexity leaves a narrow remediation window for organizations running exposed instances.
AI Agent Uncovers Unauthenticated Router Config Dump Leading to CVE Filing
An LLM agent tasked only with documenting network topology independently discovered a critical authentication bypass in a home router firmware. The agent performed read-only reconnaissance, extracted the full configuration including base64-encoded admin passwords and WPA2 keys via an unprotected CGI endpoint, and verified the finding by obtaining a valid session cookie. It then produced a complete coordinated disclosure report, classified the issue under CWE-306 with a CVSS 3.1 score of 8.8, and prepared the MITRE CVE submission package. The vulnerability affects LAN-side management interfaces of certain SOHO routers running legacy Boa web servers and remains unpatched due to inaccessible vendor firmware channels. The researcher maintained strict read-only permissions for the agent throughout the process, ensuring no configuration changes occurred. The case demonstrates how autonomous agents can accelerate vulnerability research while staying within defined operational boundaries.
AutoAddPolicy in Paramiko Disables Host Key Verification and Risks Credential Leakage After IP Reassignment
A developer discovered that fourteen deployment and management scripts all contained hardcoded references to a single VPS IP address. When the provider reassigned the address after migration, the scripts connected to an unrelated server belonging to another customer. The root cause was the line ssh.set_missing_host_key_policy(paramiko.AutoAddPolicy()), which silently accepts any host key instead of raising an exception. The connection succeeded, the root password stored in VPS_PASS was transmitted, and the operation appeared successful in logs. The author replaced AutoAddPolicy with RejectPolicy, centralized the address in a single vps.py module, and switched to key-based authentication with a password fallback. The same class of issue appears in web tools that fetch arbitrary URLs, requiring strict scheme, IP-range, and redirect checks to block SSRF vectors such as 127.0.0.1 and 169.254.169.254. The case demonstrates that host-key verification protects against routine cloud IP reuse rather than only theoretical man-in-the-middle attacks.
Developer Exposes 12 Vulnerabilities in FastAPI Todo App After 176 Bots Bypass Protections
A developer building a student-focused todo planner on FastAPI discovered that 176 of 238 new accounts were bots that bypassed three layers of protection including rate limiting and email verification. The issues stemmed from in-memory counters reset on every deployment, uvicorn trusting any X-Forwarded-For header, and email verification never being enforced in code. A full audit revealed additional flaws such as stored XSS via JSON-LD on public Q&A pages and an IDOR allowing any authenticated user to read all tasks in a project by supplying its ID. Fixes included moving rate limits to the database, properly extracting the client IP from the rightmost X-Forwarded-For entry, adding signed form timestamps, and escaping JSON for script contexts. The case highlights common pitfalls when deploying Python web services behind nginx without strict trust boundaries.