14 August 2026
Reference: CVE-2026-19149
1. What is being reported?
The issue is a 'use after free' bug in a part of Chrome called Aura, which handles graphical elements. This bug lets attackers use a specially crafted web page to break out of Chrome’s security limits on Linux systems, potentially running harmful code on the computer.
2. What this means in plain English
If your organisation uses Google Chrome on Linux, this vulnerability could let attackers run malicious software on your devices by simply visiting a dangerous website. This could lead to data theft, system damage, or other serious problems.
3. Could this affect a small business?
Small businesses using Google Chrome on Linux computers are at risk if they have not updated to the latest version. Those using other operating systems or browsers are less likely to be affected by this specific issue.
4. What to do now
- Check if your organisation uses Google Chrome on Linux devices.
- Ensure Chrome is updated to version 151.0.7922.109 or later as soon as possible.
- If you rely on an IT provider, ask them to confirm updates have been applied.
- Avoid visiting unknown or suspicious websites until updates are confirmed.
5. Ask your IT provider
Has Google Chrome on our Linux devices been updated to version 151.0.7922.109 or later to fix the critical security vulnerability CVE-2026-19149?
6. Bottom line
Update Google Chrome on Linux devices immediately to protect your organisation from a critical security risk.
Information based on CISA KEV, NVD, and reputable security reporting.