Google Chrome Update Fixes 41 Security Issues Amid Shift to AI-Powered Bug Hunting
The latest Google Chrome update has rolled out to users, patching a total of 41 security issues in version 151.0.7922.108/.109.
A dozen of these vulnerabilities were discovered by external security researchers, also known as bug bounty hunters, who are crucial to the process of identifying and reporting security threats.
The Chrome security team has been working with a Singapore-based bug bounty team, STAR Labs, which is a previous 'Master of Pwn' title holder and successful competitor at the Pwn2Own hacking events.
The update fixes two critical Common Vulnerability Exposures (CVEs), CVE-2026-19137 and CVE-2026-19170, both use-after-free memory issues in WebGL, as well as ten high-rated CVEs, including insufficient validation of untrusted input in Contextual Tasks and a heap buffer overflow in Base.
The bug bounty ecosystem is undergoing a change with the increasing use of AI tools, which can help with vulnerability discovery but also flood bug bounty programs with low-quality reports.