Chrome 150 Security Update Fixes 15 Vulnerabilities Including Two Critical Use-After-Free Flaws in Ozone (CVE-2026-15764, CVE-2026-15765)
Chrome 150 Security Update Fixes 15 Vulnerabilities (TL-2026-1368), also tracked as Chrome 150 Stable Update, is a critical-severity software vulnerability scored CVSS 8.8, first published 2026-07-15. It has no confirmed attribution, affects Google Chrome (Windows), references 15 CVEs (CVE-2026-15764, CVE-2026-15765, CVE-2026-15766), maps to 15 MITRE ATT&CK techniques (T1005, T1059.007, T1068), and is covered by 9 detection rules and 19 indicators of compromise.
Key facts for TL-2026-1368
- Threat ID
- TL-2026-1368
- Also known as
- Chrome 150 Stable Update, Chrome Ozone UAF Pair
- Severity
- CRITICAL
- CVSS
- 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- 2026-07-15
- Last reviewed
- 2026-07-15
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- all-sectors, government administration, finance, health, education, technology, retail
- Target regions
- global
- Detection rules
- 9
- Indicators of compromise
- 19
Malware and tooling in Chrome 150 Security Update Fixes 15 Vulnerabilities
Malware and tooling: issues.chromium.org bug tracker
Google shipped Chrome 150 (150.0.7871.124/.125 on Windows/macOS, 150.0.7871.124 on Linux and Android) fixing 15 vulnerabilities, including two Critical-rated use-after-free bugs in the Ozone platform-abstraction layer (CVE-2026-15764, CVE-2026-15765) that a remote attacker could exploit via a crafted HTML page and specific UI gestures to corrupt freed heap memory. Thirteen additional High/Medium-severity issues span V8, Skia, libyuv, GPU, Core, UI, HTML-in-Canvas, Media, Navigation, and Linux Toolkit Theming.
How Chrome 150 Security Update Fixes 15 Vulnerabilities works
On July 14-15, 2026 Google published the Chrome 150 Stable Channel update (150.0.7871.124/.125 for Windows and macOS, 150.0.7871.124 for Linux and Android), resolving 15 security defects reported by external and internal researchers. The two Critical-rated defects, CVE-2026-15764 and CVE-2026-15765, are both use-after-free (CWE-416) vulnerabilities in Ozone, the abstraction layer Chromium uses for platform-specific windowing, input, and graphics operations on Linux and other embedder platforms. NVD records both as CVSS 3.1 7.5 (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H) — Google's internal severity rubric rates them Critical because Ozone UAF corruption can be chained toward remote code execution or sandbox escape, materially higher than the raw CVSS base score reflects. Exploitation requires a remote attacker to convince the victim to interact with a crafted HTML page through specific UI gestures (drag, resize, or similar Ozone-routed input) that triggers the free, followed by a use of the dangling object to corrupt the heap.
The remaining 13 defects are High- or Medium-severity memory-safety and policy-enforcement bugs distributed across core rendering and scripting components: two additional use-after-free bugs (GPU process, Core), a heap buffer overflow in libyuv (CVE-2026-15767, CVSS 8.8, triggered via a crafted video file and capable of sandbox-contained arbitrary code execution), a V8 type-confusion bug (CVE-2026-15776, CWE-843, CVSS 8.8, allowing arbitrary code execution inside the renderer sandbox via a crafted HTML page), two uninitialized-memory-use information-disclosure bugs in Skia and V8 (CVE-2026-15766 and CVE-2026-15770, both CWE-457, CVSS 6.5, leaking process memory contents), insufficient policy-enforcement issues in HTML-in-Canvas and V8, an untrusted-input-validation flaw in Linux Toolkit Theming, an input-validation flaw in the Media component, an additional use-after-free in Skia, a use-after-free in UI components, and an insufficient-validation issue in Navigation rated Medium.
No public proof-of-concept or in-the-wild exploitation has been reported for any of the 15 CVEs as of publication, and none appear in the CISA Known Exploited Vulnerabilities catalog. Consistent with Chromium's standard disclosure practice, Google is withholding bug-tracker technical detail (issues.chromium.org) until a majority of the Chrome user base has updated, to slow attacker reverse-engineering of the patch diff. The update is rolling out gradually over Stable and Extended Stable channels for Windows, macOS, and Linux, plus Chrome for Android.
Credited researchers include Google's own internal security team, Microsoft researcher xinchaotian, and independent researcher Salvatore Gulizia; several credits remain unpublished (marked TBD by Google) and bug-bounty reward amounts have not yet been disclosed. Because Chrome/Chromium underpins a wide range of downstream browsers (Microsoft Edge, Brave, Opera, Vivaldi and other Chromium-based products), the fixed defects are expected to propagate into corresponding downstream security advisories in the days following this release.
MITRE ATT&CK techniques used in TL-2026-1368
Collection
Execution
T1059.007 JavaScript; T1203 Exploitation for Client Execution; T1204.001 Malicious Link; T1204.002 Malicious File
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Discovery
T1082 System Information Discovery
Initial Access
T1189 Drive-by Compromise; T1566.002 Spearphishing Link
Defense Evasion
T1211 Exploitation for Stealth; T1620 Reflective Code Loading
Resource Development
T1587.004 Exploits; T1588.005 Exploits
Reconnaissance
Affected products and versions in Chrome 150 Security Update Fixes 15 Vulnerabilities
- Google — Chrome (Windows)
Vulnerable versions: prior to 150.0.7871.124/.125
Fixed in: 150.0.7871.124/.125 - Google — Chrome (macOS)
Vulnerable versions: prior to 150.0.7871.124/.125
Fixed in: 150.0.7871.124/.125 - Google — Chrome (Linux)
Vulnerable versions: prior to 150.0.7871.124
Fixed in: 150.0.7871.124 - Google — Chrome (Android)
Vulnerable versions: prior to 150.0.7871.124
Fixed in: 150.0.7871.124 - Chromium Project — Chromium open-source browser engine
Vulnerable versions: branches prior to the 150 stable cut
Fixed in: 150 stable branch and later
Remediation for Chrome 150 Security Update Fixes 15 Vulnerabilities
Patches
- Chrome 150.0.7871.124/.125 (Windows, macOS)
- Chrome 150.0.7871.124 (Linux, Android)
Immediate actions
- Update Google Chrome to 150.0.7871.124/.125 (Windows/macOS) or 150.0.7871.124 (Linux, Android) via chrome://settings/help
- Restart the browser after update to fully apply the patched renderer/V8/GPU binaries
- Force-push the Chrome update via enterprise management (Chrome Browser Cloud Management, Google Admin console, or GPO) rather than waiting for the default gradual rollout
- Update any Chromium-based downstream browsers (Microsoft Edge, Brave, Opera, Vivaldi) once their corresponding security advisories ship
Workarounds
- No effective workaround short of patching; disabling JavaScript/Canvas or restricting video playback reduces but does not eliminate individual attack surfaces (V8, HTML-in-Canvas, libyuv) while leaving Ozone UAF paths exposed
Longer-term hardening
- Enable Site Isolation and ensure renderer sandboxing policies remain enforced in managed Chrome deployments
- Track Chromium security release notes and CVE feeds for recurring UAF/type-confusion classes in Ozone, V8, and Skia to prioritize patch cadence
- Restrict or monitor untrusted video/HTML content ingestion paths (e.g., email gateways, web proxies) that could deliver crafted trigger files for libyuv/V8 bugs
- Maintain endpoint detection coverage for renderer-process crash-then-respawn patterns consistent with failed or successful UAF exploitation attempts
CVEs associated with Chrome 150 Security Update Fixes 15 Vulnerabilities
- CVE-2026-15764
- CVE-2026-15765
CVE-2026-15766CVE-2026-15767CVE-2026-15768CVE-2026-15769CVE-2026-15770CVE-2026-15771CVE-2026-15772CVE-2026-15773CVE-2026-15774CVE-2026-15775CVE-2026-15776CVE-2026-15777CVE-2026-15778
Weaknesses (CWE) in Chrome 150 Security Update Fixes 15 Vulnerabilities
CWE-416, CWE-457, CWE-843, CWE-122
Timeline of Chrome 150 Security Update Fixes 15 Vulnerabilities
- CVE-2026-15764 (Ozone use-after-free) reported to Google's Chrome security team via the Chromium issue tracker.
- CVE-2026-15765, the second Critical Ozone use-after-free, reported via the Chromium issue tracker.
- CVE-2026-15776, a V8 type-confusion bug enabling sandboxed arbitrary code execution, reported via the Chromium issue tracker.
- Google publishes the Chrome 150 Stable Channel Update blog post on chromereleases.googleblog.com listing all 15 fixed CVEs.
- Google states the update will continue rolling out over the coming days to weeks across managed and consumer channels.
- Threat surfaced via Cyber Security News advisory coverage and ingested into the TL-Intel hunt pipeline.
- Google Chrome for Android updated to 150.0.7871.124, closing the same set of vulnerabilities on the mobile platform.
- Chrome 150.0.7871.124/.125 (Windows/macOS) and 150.0.7871.124 (Linux) begin gradual Stable and Extended Stable channel rollout.
Sources cited for Chrome 150 Security Update Fixes 15 Vulnerabilities
- Chrome 150 Security Update: Vulnerability Summary
- Stable Channel Update for Desktop
- Google Chrome Update Fixes 15 Security Flaws, Including Critical Ozone UAF Flaws
- Chrome 150 Security Update Patches 15 Flaws, Including Two Critical Code Execution Ones
- NVD - CVE-2026-15764
- NVD - CVE-2026-15765
- NVD - CVE-2026-15766
- NVD - CVE-2026-15767
- NVD - CVE-2026-15770
- NVD - CVE-2026-15776
- Chromium Issue Tracker - Ozone UAF (CVE-2026-15764)
- Chromium Issue Tracker - Ozone UAF (CVE-2026-15765)
- Chromium Issue Tracker - Skia Uninitialized Use (CVE-2026-15766)
- Chromium Issue Tracker - libyuv Heap Overflow (CVE-2026-15767)
- Chromium Issue Tracker - V8 Uninitialized Use (CVE-2026-15770)
Threats related to Chrome 150 Security Update Fixes 15 Vulnerabilities
- Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flaws
- Google Chrome 149.0.7827.53 — 429 Vulnerabilities Patched (22 Critical); Critical ANGLE/GPU Memory-Safety Sandbox-Escape Chain (CVE-2026-10881 / CVE-2026-10883 / CVE-2026-10898)
- Multi-Vendor Critical Patch Roundup: Firefox 152.0.6, Chrome 150, Adobe ColdFusion/Commerce/AEM (APSB26-68/73/74), and VMware Avi Load Balancer (VMSA-2026-0005)
- Multiple Vulnerabilities in Firefox 152 Enable Remote Code Execution and Sandbox Escape (MFSA 2026-57)
- Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity Vulnerabilities (CVE-2026-16413 through CVE-2026-16424)
- Critical Type Confusion in isolated-vm (GHSA-864f-rcv7-6rh4) Enables Sandbox Escape and RCE on Host
Detection coverage for TL-2026-1368
As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1368 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.