Brave releases security update to patch critical Chromium flaws in version 1.93.138

Brave has rolled out version 1.93.138, fixing a critical use-after-free flaw and six high-severity vulnerabilities in Chromium, highlighting the importance of updating individual browsers independently.

Brave has issued version 1.93.138, bringing desktop and Android users onto Google’s Chromium build 151.0.7922.173. The update matters because it closes a critical use-after-free flaw in Chromoting, alongside six high-severity vulnerabilities in Chromium’s wider code base. According to Brave’s release notes and Google’s stable-channel bulletin, the patch applies across the browser’s supported platforms and is the version users should now be running.

The most serious issue is CVE-2026-76017, a use-after-free bug in Chromoting, the remote-desktop component used within Chromium. The US National Vulnerability Database says the flaw affected Chrome versions before 151.0.7922.173 and could allow a remote attacker to execute arbitrary code outside the browser sandbox through crafted network traffic. Google also fixed six further high-severity problems affecting areas including privilege elevation, authorisation, V8, the DOM, networking and Linux theming.

For Brave users, the practical point is straightforward: updating Chrome, Edge or another Chromium-based browser does not update Brave. The fix is delivered through Brave’s own updater. On desktop, users should open the browser menu, choose Help, then About Brave, or go directly to brave://settings/help, wait for the update to download, and relaunch the browser. On Android, the update comes via Google Play and should then be confirmed in Brave’s About screen.

The latest release notes on Brave’s own site show that 1.93.138 supersedes 1.93.137, which had only moved Chromium to 151.0.7922.169. That distinction matters because Brave users who stopped at the earlier build would still miss the latest security fixes. Google has not said the flaws are being actively exploited, and they are not currently listed by CISA in its Known Exploited Vulnerabilities catalogue, but the severity of the patched bugs makes the update one that should not be deferred.

Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.