The browser refresh eliminates over two dozen memory safety bugs, including critical use-after-free flaws. The post Critical Vulnerabilities Patched With Chrome 151 Update appeared first on SecurityWeek.

Google has released an update for its Chrome browser, version 151, which addresses a significant number of security vulnerabilities. The update is reported to patch more than two dozen memory safety bugs, a category of flaw that often leads to severe security issues. Among these, several critical use-after-free vulnerabilities were specifically highlighted as being resolved.
Use-after-free (UAF) vulnerabilities occur when a program attempts to use memory after it has been freed. This can lead to various unpredictable behaviors, including crashes, corruption of data, or, critically, arbitrary code execution. Attackers can exploit UAF flaws by manipulating the timing of memory allocation and deallocation to insert malicious code into the freed memory region before it is reused by legitimate program operations. When the program then attempts to access the "freed" memory, it inadvertently executes the attacker's code.
Memory safety bugs, as a broader category, encompass a range of issues where a program interacts with memory in an unsafe or unintended way. Besides use-after-free, this can include buffer overflows, out-of-bounds reads and writes, and double-free errors. These types of flaws are particularly prevalent in software developed in languages like C and C++, which offer direct memory management but require careful handling to prevent such vulnerabilities. Modern browsers, being complex applications with extensive C++ codebases, are frequently targets for discovering and exploiting these kinds of issues.
The scope of impact for browser vulnerabilities like these is typically broad, affecting a large user base given Chrome's widespread adoption across various operating systems. Exploitation of such flaws could allow an attacker to execute arbitrary code within the context of the browser, potentially leading to system compromise, data theft, or further network penetration. Users are generally advised to update their browsers promptly to mitigate the risk posed by these patched vulnerabilities.
Mitigation for memory safety issues often involves adopting safer programming practices, utilizing memory-safe languages where feasible, and employing robust testing methodologies, including fuzzing and static analysis. For end-users, the primary mitigation strategy is to ensure that their software, especially web browsers, is kept up-to-date. Browser vendors typically push updates automatically, but users should verify that updates are applied or manually trigger them if necessary.
This update underscores the continuous effort required to maintain the security of widely used software like web browsers. The regular discovery and patching of critical vulnerabilities, particularly memory safety issues, highlight the ongoing cat-and-mouse game between security researchers, developers, and malicious actors. It reinforces the industry-wide understanding that proactive patching and user vigilance are essential components of a robust cybersecurity posture in the face of persistent threats.

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked a

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs