Security NEXT•August 19, 2026•🇯🇵Translated from Japanese

Google Releases Chrome Security Update Fixing 15 Vulnerabilities Including Two Critical Flaws

Google has released a security update for its browser Chrome on August 18, 2026, local time. The update fixes multiple vulnerabilities, including two rated as critical in severity.

The company released Chrome 151.0.7922.170 and Chrome 151.0.7922.169 for Windows and macOS, along with Chrome 151.0.7922.169 for Linux. These versions address a total of 15 vulnerabilities, 11 of which were reported by Google itself. The rollout is scheduled to occur gradually over the next several days to weeks.

Two vulnerabilities are classified at the highest severity level of critical. These are a buffer overflow in WebGL tracked as CVE-2026-76034 and a buffer overflow in Dawn tracked as CVE-2026-76036. Both issues were reported by Google after mid-July.

Thirteen additional vulnerabilities rated high severity were also resolved. These include type confusion and calculation errors in the V8 script engine, Use After Free flaws in Browser and WebGL, buffer overflows in ANGLE, and information disclosure issues in Skia.

Other fixes address implementation flaws in CORS, link handling problems in CredentialProvider, race conditions in USB, and the use of uninitialized resources in GPU components.

The complete list of patched vulnerabilities is as follows:

  • CVE-2026-76033
  • CVE-2026-76034
  • CVE-2026-76035
  • CVE-2026-76036
  • CVE-2026-76037
  • CVE-2026-76038
  • CVE-2026-76039
  • CVE-2026-76040
  • CVE-2026-76041
  • CVE-2026-76042
  • CVE-2026-76043
  • CVE-2026-76044
  • CVE-2026-76045
  • CVE-2026-76046
  • CVE-2026-76047

Related articles

Habr•Vulnerabilities & Exploits

Dissecting CVE-2026-83557 in jackson-databind: Why Not Every CVE Requires Immediate Panic

A detailed analysis of CVE-2026-83557 reveals that the vulnerability in jackson-databind affects only a narrow set of configurations involving polymorphic deserialization with the Comparable base type. The flaw stems from an incomplete denylist in DefaultBaseTypeLimitingValidator, which overlooks java.lang.Comparable when the MapperFeature.BLOCK_UNSAFE_POLYMORPHIC_BASE_TYPES flag is explicitly enabled. Researchers constructed working proof-of-concept exploits showing that an attacker can instantiate classes such as java.io.File, but only when the property is declared as Comparable<?> and the protective flag is active. The issue impacts versions 2.11 through 2.22.1, yet the CVSS score of 5.6 reflects its moderate real-world risk because most applications lack the required Comparable-typed polymorphic fields. Patching introduces its own trade-off by blocking legitimate Comparable subclasses, forcing developers to implement custom BasicPolymorphicTypeValidator allowlists. The case highlights how dependency scanners often flag CVEs without considering application-specific configuration and DTO structures.

Security NEXT•Vulnerabilities & Exploits

Multiple Critical Vulnerabilities Found in Citrix NetScaler ADC and Gateway, Two Actively Exploited

Cloud Software Group disclosed eight vulnerabilities affecting NetScaler ADC and NetScaler Gateway products on September 27, 2026. Two of the issues, CVE-2026-88771 and CVE-2026-88772, have already been confirmed as exploited in the wild, prompting urgent remediation advice. CVE-2026-88771 stems from insufficient input validation and allows unauthenticated remote code execution across all default configurations. CVE-2026-88772 involves a memory overflow that can lead to code execution or denial of service when DTLS is enabled, which occurs by default on VPN vServers. The remaining six vulnerabilities cover code execution, denial of service, and HTTP request smuggling risks, with the advisory rated Critical overall. Organizations are urged to apply patches immediately and investigate potential breaches.

Habr•Vulnerabilities & Exploits

YApi Abandoned Since 2022: Fork Yapix Exposes Forgable Project Tokens and Critical Sandbox Flaws

YApi, a widely used open-source API documentation and mocking platform with 27.7k GitHub stars, has received no updates since its 1.12 release in November 2022. The project accumulated 1,629 open issues, including an unaddressed remote code execution report via mock scripts. Security researcher Perruer created the Yapix fork to address broken dependencies, Node.js 22 incompatibility with deprecated crypto.createCipher, and 244 known vulnerabilities in production dependencies. Analysis revealed that project tokens could be forged by any user because the default passsalt key was a hardcoded five-character string published on GitHub. The original implementation used vm2 and Node vm for script execution, both of which are unsafe, allowing arbitrary server-side code execution. Yapix migrates to isolated-vm with strict memory and time limits, replaces SHA-1 password hashing with scrypt, and blocks MongoDB operator injection in API parameters.

Habr•Vulnerabilities & Exploits

Researchers Bypass RP2350 Secure Debug Lock with Laser Fault Injection and Photon Emission Microscopy

Security researchers have demonstrated a hardware attack that restores Secure Debug access on the RP2350 microcontroller revision A4 despite permanent OTP fuses disabling it. Using photon emission microscopy they first located the exact physical bits of the DEBUGEN register, then applied precisely timed 980 nm laser pulses to flip two critical bits and re-enable the Mem-AP ports. The attack requires decapping the chip from the backside and laboratory equipment costing around $250,000, but succeeds in seconds once calibrated. It bypasses the CRIT1.DEBUG_DISABLE fuse, TrustZone restrictions, and glitch detectors by resetting the device before firmware can re-lock the OTP page. The technique was developed against the updated A4 silicon released after the first Raspberry Pi Hacking Challenge. The work highlights that even heavily hardened microcontrollers remain vulnerable to sophisticated physical attacks when an attacker has direct silicon access.