HomeIntelligenceBrief
VULNERABILITY BRIEF🟠 High Vulnerability

Multiple Chrome Vulnerabilities (CVE‑2026‑19137 to CVE‑2026‑19175) Could Enable Arbitrary Code Execution

CIS disclosed 23 Chrome flaws that could let an attacker run code as the logged‑in user. Organizations must patch promptly and capture remediation evidence to satisfy SOC 2 control mapping requirements.

LiveThreat™ Intelligence · 📅 August 07, 2026· 📰 cisecurity.org
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
cisecurity.org

Multiple Chrome Vulnerabilities (CVE‑2026‑19137 to CVE‑2026‑19175) Could Enable Arbitrary Code Execution

What Happened — CIS disclosed a set of 23 newly‑identified flaws in Google Chrome (versions < 151.0.7922.108/109). Several use‑after‑free, out‑of‑bounds write, and heap‑buffer overflow bugs could let an attacker execute arbitrary code in the context of the logged‑in user, potentially installing software, modifying data, or creating privileged accounts. No public exploits have been observed yet.

Why It Matters for Compliance & Audit Readiness

  • Unpatched client‑side software creates a control gap that defeats SOC 2 CC6.1 (System Operations) and CC7.1 (Change Management) requirements for maintaining a secure, up‑to‑date environment.
  • Continuous evidence of patch status and remediation timelines is essential to demonstrate due diligence during a SOC 2 audit.
  • Verisq’s Control Mapping capability lets you map each Chrome CVE to the relevant SOC 2 control, auto‑collect remediation evidence, and store it in the Trust Center for audit reviewers.

Who Is Affected – Enterprises, government agencies, and any organization that permits Chrome on employee workstations (Windows, macOS, Linux).

Recommended Actions

  • Verify Chrome versions across all endpoints; prioritize updates to 151.0.7922.108 or later.
  • Integrate Chrome patch status into your continuous compliance dashboard; map the remediation to SOC 2 CC6.1 and CC7.1 controls.
  • Retain patch‑deployment logs in a tamper‑evident repository for audit evidence.

Source: CIS Advisory 2026‑078

Technical Notes – The flaws span WebGL, Aura, Skia, V8, GPU, and other Chrome subsystems. Exploitation requires drive‑by compromise (TA0001/T1189). CVE identifiers include CVE‑2026‑19137, CVE‑2026‑19170, CVE‑2026‑19149, CVE‑2026‑19157, CVE‑2026‑19168, CVE‑2026‑19138, CVE‑2026‑19139, CVE‑2026‑19144, CVE‑2026‑19162, CVE‑2026‑19175, etc.

📰 Original Source
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-078

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Every gap like this maps to a control you can evidence.

The Verisq AI Trust Operations platform maps incidents to your control framework and collects the evidence continuously — so your Trust Center shows proof, not promises, when a buyer or auditor asks.

Explore the Verisq AI Trust Operations platform →