The Google Chrome security machine continues to push out updates to the world’s most popular web browser, which is obviously a good thing. The latest, which updates Chrome to version 151.0.7922.108/.109 for Windows, Mac and Linux users, is now rolling out to users and fixes a total of 41 security issues. Importantly, and I’ll get to why momentarily, a dozen of these were disclosed by what Google calls external security researchers. Bug bounty hunters, and that’s the ideal description of the task they perform, have been at the center of the vulnerability discovery process for the longest time. The critical question is: as AI tools and systems continue to drive a wedge into the bug bounty ecosystem, can they survive?

Google Chrome 151.0.7922.108/.109 Security Update Rolls Out

As the latest Chrome security update starts rolling out to users, with Google confirming it should reach them over the coming days, it didn’t escape my notice that almost 30% of the vulnerabilities fixed in this release were disclosed by Google bug bounty hunters. And that, dear reader, fills my heart with joy as a cybersecurity veteran, because it validates the importance of the human hacker in this age of AI-creep. But before I get into that, let’s take a look at the delectable dozen Common Vulnerabilities and Exposures, two of which achieved a Common Vulnerability Scoring System severity rating of critical.

The two critical CVEs were CVE-2026-19137 and CVE-2026-19170, both use-after-free memory issues in WebGL. The first reported by anonymous researcher, the second by Muhammad Alifa Ramdhan, Pan ZhenPeng and Billy Jheng Bing Jhong of STAR Labs. If the name STAR Labs sounds familiar, it’s because this Singapore-based bug bounty team is a previous “Master of Pwn” title holder and very successful competitor at the Pwn2Own hacking events.

There were also ten high-rated CVEs, as follows:

  • CVE-2026-19169 is an insufficient validation of untrusted input in Contextual Tasks, reported by Sven Dysthe.
  • CVE-2026-19168 is an inappropriate implementation in Chrome’s V8 JavaScript rendering engine, reported by XBOW and triaged by Andrés Luksenberg.
  • CVE-2026-19156 is a heap buffer overflow in Base, reported by Viktoria Zlatinova.
  • CVE-2026-19165 is yet another use-after-free memory vulnerability in Extensions, and was reported by @bean5oup.
  • CVE-2026-19166 is also a use-after-free issue, this time in Web Authentication, and reported by heesun.
  • CVE-2026-19173, meanwhile, is an out-of-bounds problem in Skia that was reported by Vu Van Tien.
  • CVE-2026-19174 an integer overflow in V8 reported by Seunghyun Lee (@0x10n) of QED Audit.
  • CVE-2026-19176 a use-after-free in Skia reported by WinD39 – Huynh Dinh Vu.
  • And finally, CVE-2026-19177, an insufficient validation of untrusted input in the Chrome UI, which was reported by Fabian Wahle of Hap Security.

This Chrome memory vulnerability explainer will help you understand why this genre of security issue continues to affect the web browser.

The Importance Of Google Chrome Bug Bounty Hunters

But here’s the thing: the business of vulnerability discovery and reporting is undergoing a sea change thanks to the inevitable impact of AI on the bug bounty ecosystem. This is something of a double-edged sword: AI tooling helps with both tasks, which leads to more “vulnerabilities” being discovered, while simultaneously flooding bug bounty programs with more often than not low-quality and unverified reports. Indeed, this deluge of AI slop, and there’s no better word for it, has led some vulnerability disclosure platforms to suspend or limit reporting.

A Google spokesperson has confirmed “the ongoing value of engaging with the external security research community to make Google and its products safer.” And there lies the rub: the external security research community, not an agentic one. Real human hackers with real human skills. The future sits with vetted researchers capable of both finding and validating vulnerabilities. Sure, AI can help with this process from initial discovery to report writing, but the human hand is still needed at every stage.

Share.
Exit mobile version