Google has released a Chrome update that closes 41 security holes, and it is worth applying the same day rather than waiting for the browser to restart on its own schedule. Hong Kong's national CERT, HKCERT, flagged the release in a security bulletin on August 7, rating it medium risk and listing the possible impacts as remote code execution, information disclosure, denial of service, security restriction bypass and data manipulation.
What's affected
Anything older than the fixed build is in scope, which for most people means a browser that has been left open for a while. The fixed versions are 151.0.7922.108 on Linux, and 151.0.7922.108 or .109 on both Mac and Windows. The advisory covers the desktop stable channel. Users of other Chromium-based browsers do not get these fixes from Google directly and should watch for their own vendor's update.
What we know, and what we don't
The bulletin lists 41 vulnerability identifiers, running from CVE-2026-19137 to CVE-2026-19177. It does not publish a severity score for any individual issue, does not single out which of the 41 is the most serious, and says nothing about any of them being exploited in attacks. Google's stable channel release note is the primary source and carries the per-bug detail, including which flaws were reported by outside researchers. We are not going to reconstruct how any of these bugs work from a CVE list; the impact categories above are what the advisory actually asserts.
What is fair to say is that "remote code execution" in a browser context means a page you visit could potentially run code on your computer, which is why browser updates carry more urgency than most. Chrome fixes generally reach users quietly in the background, but the new build does not take effect until the browser is restarted, and long-lived sessions with dozens of tabs are exactly the ones that tend to sit unpatched for days.
What you should do
Open the Chrome menu, then Help, then About Google Chrome. The browser checks for an update on that screen and shows a Relaunch button when one has been downloaded. Click it. Confirm afterwards that the version shown is 151.0.7922.108 or later on Linux, or 151.0.7922.108 or .109 or later on Mac and Windows.
Fleet administrators should push the build rather than rely on individual restarts, and check managed policies that pin Chrome to an older version. This is the second large batch of Chrome fixes we have covered in recent weeks, after the 382-bug Chrome 150 release in July, and the browser remains one of the highest-value targets on any endpoint precisely because it renders untrusted content all day.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.