Google Chrome 150.0.7871.114/.115 Patches 27 Vulnerabilities Including Two Critical Use-After-Free Flaws (CVE-2026-15112, CVE-2026-15129) — Threadlinqs Intelligence
As of 2026-07-19, Google Chrome 150.0.7871.114/.115 Patches 27 Vulnerabilities Including Two Critical Use-After-Free Flaws (CVE-2026-15112, CVE-2026-15129) is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1173 · Severity: HIGH · CVSS: 8.8 · Status: PATCHED · Category: VULNERABILITY
Updated: 2026-07-19 · revalidated 1× · latest source
Google shipped two Chrome Stable updates on consecutive days (July 7-8, 2026), culminating in 150.0.7871.114/.115, which fixes 27 security vulnerabilities including two critical use-after-free bugs in
On July 7-8, 2026, Google released back-to-back Chrome Stable channel updates for Windows, macOS, and Linux (150.0.7871.114/.115), following an earlier 150.0.7871.100/.101 push on July 7. The combined update batch addresses 27 security vulnerabilities discovered via internal audits, fuzzing (AddressSanitizer, MemorySanitizer, Control Flow Integrity, libFuzzer, AFL, Valgrind), and external bug-bounty submissions through the Chrome Vulnerability Reward Program (VRP).
The two vulnerabilities rated Critical are both use-after-free (CWE-416) memory-safety bugs: CVE-2026-15112 in the Ozone platform-abstraction layer (Chrome's windowing/graphics backend used on Linux and ChromeOS-adjacent builds), described by vendor/aggregator analysis as enabling memory corruption leading to arbitrary code execution, and CVE-2026-15129 in the Views UI toolkit (Chrome's native desktop widget framework), described as heap corruption with sandbox-escape potential. Both carry a CVSS 3.1 base score of 8.8 (AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) and are described by NVD/Chromium as allowing 'a remote attacker to potentially exploit heap corruption via a crafted HTML page' — meaning a victim need only load an attacker-controlled or attacker-compromised web page (drive-by/client-side vector) for exploitation to begin, no additional privileges required, but requiring some form of user interaction (e.g., navigating to the page). Secondary reporting notes that use-after-free bugs of this class are 'particularly dangerous because they can be leveraged to corrupt the heap, potentially leading to sandbox escapes or full system compromise when combined with other bugs' — i.e., chained with a renderer sandbox-escape or a second info-leak/UAF bug.
The remaining 25 vulnerabilities span a wide range of Chrome subsystems, each mapped to a distinct component and bug class: use-after-free bugs in Extensions (CVE-2026-15110), Views (CVE-2026-15111), Autofill (CVE-2026-15113), Actor (CVE-2026-15116), Payments (CVE-2026-15117), Input (CVE-2026-15118), Core (CVE-2026-15120), WebRTC (CVE-2026-15121), Forms (CVE-2026-15126), IndexedDB (CVE-2026-15107, Medium), and InterestGroups/Privacy Sandbox (CVE-2026-15133); uninitialized-memory use in V8 the JavaScript engine (CVE-2026-15132) and ANGLE the graphics-translation layer (CVE-2026-15109); integer overflow in the Extensions API (CVE-2026-15108); out-of-bounds read/write in Codecs (CVE-2026-15114); insufficient input/data validation in Codecs (CVE-2026-15122), WebAppInstalls (CVE-2026-15115), DOM (CVE-2026-15123), and Navigation (CVE-2026-15131, Medium); insufficient policy enforcement in Passwords (CVE-2026-15124) and Navigation (CVE-2026-15130); and inappropriate-implementation flaws in GetUserMedia/WebRTC media capture (CVE-2026-15119), Forms (CVE-2026-15125, CVE-2026-15128), and WebGL (CVE-2026-15127).
The breadth of affected subsystems — extensions, payments/autofill (sensitive user data), WebRTC/GetUserMedia (camera/microphone access APIs), WebGL (GPU-process attack surface), and password management — means the batch is not limited to a single attack surface: a threat actor with a working exploit for the two Critical UAFs (Ozone/Views) could pursue initial code execution via a crafted page, while several of the High-severity bugs (Extensions, Payments, Autofill, Passwords, WebRTC/GetUserMedia) represent secondary risk to sensitive browser-managed data and device peripherals (camera/mic) if independently or chain-exploited.
Notable VRP-credited researchers include Pierre Langlois of Arm (CVE-2026-15132, uninitialized use in V8, $500 reward), Jihyeon Jeong of Compsec Lab, Seoul National University (CVE-2026-15133, use-after-free in InterestGroups, $500 reward), and zh1x1an1221 of Ant Group (CVE-2026-15107, use-after-free in IndexedDB, $2,000 reward). Corresponding fixes shipped to Chrome for Android (150.0.7871.114) and iOS (150.0.7871.113). This release followed an earlier, larger Chrome 150 stable rollout around July 2,
Weaknesses (CWE)
CWE-416, CWE-190, CWE-457, CWE-20, CWE-1288, CWE-693, CWE-125, CWE-787, CWE-1021, CWE-284
Target sectors: all-sectors-generic-browser-user-base, enterprise-endpoint, government administration, finance, health, education, consumer
Target regions: global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2026-15107, CVE-2026-15108, CVE-2026-15109, CVE-2026-15110, CVE-2026-15111, CVE-2026-15112, CVE-2026-15113, CVE-2026-15114, CVE-2026-15115, CVE-2026-15116, T1588, T1189, T1203, T1204, T1176, T1068, T1211, T1562, T1518, T1555