[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fbtleAObN0eJ_7JyQm8y415M01cVDFwAkCGXUGlL01XE":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":20,"created_at":21,"published_at":22,"article":23,"tags":27,"podcasts":40},"fc2748db-da3b-46f7-b1d3-272c9cea794f","chrome-151-patches-370-vulnerabilities-including-7-critical-bugs","be9eb138-0679-404a-8983-53732ab72efc","Chrome 151 Patches 370 Vulnerabilities Including 7 Critical Bugs","Google's release of Chrome 151 addressing 370 vulnerabilities — including seven critical use-after-free and race condition flaws — highlights the relentless pace at which browser attack surfaces expand. Use-after-free vulnerabilities are particularly dangerous as they can allow attackers to execute arbitrary code simply by luring a user to a malicious webpage. The sheer volume of defects (292 medium\u002Flow plus 71 high-severity) demonstrates that even widely trusted software requires continuous security scrutiny. Organizations that delay browser updates expose employees and corporate systems to exploitation of publicly disclosed vulnerabilities, making rapid patch deployment essential.","**Immediate actions:**\n- Deploy Chrome 151 immediately across all endpoints by pushing the update via your enterprise management platform (e.g., Google Admin, Intune, or SCCM).\n- Verify browser version compliance on all managed devices using an endpoint detection or asset inventory tool within 24–48 hours of release.\n- Temporarily restrict access to untrusted or high-risk websites on unpatched endpoints until the update is confirmed deployed.\n\n**Long-term improvements:**\n- Enable automatic browser updates enterprise-wide and enforce a maximum patch lag policy (e.g., critical patches applied within 48 hours).\n- Maintain a comprehensive, real-time inventory of all browser versions across endpoints to quickly identify unpatched assets.\n- Establish a formal vulnerability management program that tracks vendor advisories (e.g., Google Chrome Releases RSS) and triggers patch workflows automatically.\n\n**Detection measures:**\n- Configure endpoint detection and response (EDR) tools to alert on exploitation indicators associated with use-after-free or memory corruption patterns.\n- Implement web proxy or DNS filtering to block known malicious domains that exploit browser vulnerabilities while patching is in progress.",[12,13,14,15,16,17,18,19],"CIS Control 2: Inventory and Control of Software Assets","CIS Control 7: Continuous Vulnerability Management","NIST SP 800-40 Rev. 4: Guide to Enterprise Patch Management Planning","NIST CSF ID.VM-1: Vulnerabilities in assets are identified and documented","NIST CSF RS.MI-3: Newly identified vulnerabilities are mitigated or documented as accepted risks","ISO\u002FIEC 27001:2022 Annex A 8.8: Management of technical vulnerabilities","ITIL v4: Change Enablement (emergency change process for critical patches)","NIST SP 800-128: Security-Focused Configuration Management","published","2026-07-30T08:20:24.017134+00:00","2026-07-30T08:20:23.911+00:00",{"id":7,"url":24,"slug":25,"title":26},"https:\u002F\u002Fwww.securityweek.com\u002Fchrome-151-patches-370-vulnerabilities\u002F","chrome-151-patches-370-vulnerabilities-4aa728","Chrome 151 Patches 370 Vulnerabilities",[28,34],{"id":29,"name":30,"slug":31,"description":32,"color":33},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":35,"name":36,"slug":37,"description":38,"color":39},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",[]]