13 August 2026
Reference: CVE-2026-19138
1. What is being reported?
The report describes a weakness in Google Chrome’s crash reporting system that could allow a hacker who already controls part of the browser to escape its safety limits and run harmful code on your device. This is done by tricking Chrome with a specially made web page.
2. What this means in plain English
If your organisation uses Google Chrome and it is not updated, attackers could use this flaw to gain deeper access to your computer, potentially stealing data or causing damage. This is a high-risk issue because it can be exploited remotely without needing physical access.
3. Could this affect a small business?
Any small business, charity, club or office using Google Chrome on Windows or other supported systems could be affected if they have not installed the latest updates. Those who do not use Chrome or keep it updated are less likely to be at risk.
4. What to do now
- Check which version of Google Chrome you are using on all your devices.
- Update Google Chrome immediately to version 151.0.7922.109 or later.
- If you use managed devices, ensure your IT provider applies this update promptly.
- Ask your IT provider to confirm that no systems remain vulnerable to this issue.
5. Ask your IT provider
Can you confirm that all our Google Chrome browsers are updated to the latest version to protect against the CVE-2026-19138 vulnerability?
6. Bottom line
Keep Google Chrome up to date to protect your organisation from serious security risks.
Information based on NVD, CISA KEV, and reputable security reporting.