Affected Systems

Google Chrome versions 149, 150, and 151 (released June–July 2026). All prior Chrome versions are affected by the resolved vulnerabilities. One critical flaw (CVE-2026-3545, CVSS 9.6) is a 13-year-old sandbox escape in Navigation component, patched in March 2026.

Exploitation Status

CVE-2026-3545 (critical sandbox escape) was patched in March 2026; no active exploitation mentioned. The surge in vulnerabilities is driven by AI-powered discovery (LLMs), with bugs being reported faster than vendors can patch. Google warns of "fast-moving, AI-powered attacks" and is accelerating release cadence to twice-weekly security updates.

Business Impact

Organizations face an unprecedented volume of browser vulnerabilities due to AI-accelerated discovery. Chrome's shift to two security releases per week increases patch management overhead. The 13-year latency of CVE-2026-3545 highlights long-standing exposure risk. Google is piloting dynamic patching (no restart required) and automated CVE generation to reduce time-to-patch, but enterprises must ensure rapid update deployment to stay ahead of AI-enabled attackers exploiting newly disclosed flaws.

Urgency

🟠 Within 24 hours

Recommended Actions

  • Update all Chrome installations to version 151 or later immediately via enterprise update mechanisms (e.g., Google Update for Business, WSUS, or MDM policies).
  • Enable automatic Chrome updates and verify update compliance across endpoints using Chrome Browser Cloud Management or equivalent telemetry.
  • Monitor Chrome release notes and CVE disclosures weekly at https://chromereleases.googleblog.com/ due to accelerated twice-weekly security release schedule.
  • Test and deploy Chrome's dynamic patching features (available Chrome 150+) to reduce restart delays and improve patch application speed.
  • Review endpoint detection logs for exploitation attempts targeting CVE-2026-3545 (sandbox escape via Navigation component) on systems running Chrome versions prior to March 2026 patch.