Chrome 150 Security Update Fixes 15 Vulnerabilities Including Two Critical Use-After-Free Flaws in Ozone (CVE-2026-15764, CVE-2026-15765)

Chrome 150 Security Update Fixes 15 Vulnerabilities (TL-2026-1368), also tracked as Chrome 150 Stable Update, is a critical-severity software vulnerability scored CVSS 8.8, first published 2026-07-15. It has no confirmed attribution, affects Google Chrome (Windows), references 15 CVEs (CVE-2026-15764, CVE-2026-15765, CVE-2026-15766), maps to 15 MITRE ATT&CK techniques (T1005, T1059.007, T1068), and is covered by 9 detection rules and 19 indicators of compromise.

Key facts for TL-2026-1368

Threat ID
TL-2026-1368
Also known as
Chrome 150 Stable Update, Chrome Ozone UAF Pair
Severity
CRITICAL
CVSS
8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Status
PATCHED
Category
VULNERABILITY
First published
2026-07-15
Last reviewed
2026-07-15
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
all-sectors, government administration, finance, health, education, technology, retail
Target regions
global
Detection rules
9
Indicators of compromise
19

Malware and tooling in Chrome 150 Security Update Fixes 15 Vulnerabilities

Malware and tooling: issues.chromium.org bug tracker

Google shipped Chrome 150 (150.0.7871.124/.125 on Windows/macOS, 150.0.7871.124 on Linux and Android) fixing 15 vulnerabilities, including two Critical-rated use-after-free bugs in the Ozone platform-abstraction layer (CVE-2026-15764, CVE-2026-15765) that a remote attacker could exploit via a crafted HTML page and specific UI gestures to corrupt freed heap memory. Thirteen additional High/Medium-severity issues span V8, Skia, libyuv, GPU, Core, UI, HTML-in-Canvas, Media, Navigation, and Linux Toolkit Theming.

How Chrome 150 Security Update Fixes 15 Vulnerabilities works

On July 14-15, 2026 Google published the Chrome 150 Stable Channel update (150.0.7871.124/.125 for Windows and macOS, 150.0.7871.124 for Linux and Android), resolving 15 security defects reported by external and internal researchers. The two Critical-rated defects, CVE-2026-15764 and CVE-2026-15765, are both use-after-free (CWE-416) vulnerabilities in Ozone, the abstraction layer Chromium uses for platform-specific windowing, input, and graphics operations on Linux and other embedder platforms. NVD records both as CVSS 3.1 7.5 (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H) — Google's internal severity rubric rates them Critical because Ozone UAF corruption can be chained toward remote code execution or sandbox escape, materially higher than the raw CVSS base score reflects. Exploitation requires a remote attacker to convince the victim to interact with a crafted HTML page through specific UI gestures (drag, resize, or similar Ozone-routed input) that triggers the free, followed by a use of the dangling object to corrupt the heap.

The remaining 13 defects are High- or Medium-severity memory-safety and policy-enforcement bugs distributed across core rendering and scripting components: two additional use-after-free bugs (GPU process, Core), a heap buffer overflow in libyuv (CVE-2026-15767, CVSS 8.8, triggered via a crafted video file and capable of sandbox-contained arbitrary code execution), a V8 type-confusion bug (CVE-2026-15776, CWE-843, CVSS 8.8, allowing arbitrary code execution inside the renderer sandbox via a crafted HTML page), two uninitialized-memory-use information-disclosure bugs in Skia and V8 (CVE-2026-15766 and CVE-2026-15770, both CWE-457, CVSS 6.5, leaking process memory contents), insufficient policy-enforcement issues in HTML-in-Canvas and V8, an untrusted-input-validation flaw in Linux Toolkit Theming, an input-validation flaw in the Media component, an additional use-after-free in Skia, a use-after-free in UI components, and an insufficient-validation issue in Navigation rated Medium.

No public proof-of-concept or in-the-wild exploitation has been reported for any of the 15 CVEs as of publication, and none appear in the CISA Known Exploited Vulnerabilities catalog. Consistent with Chromium's standard disclosure practice, Google is withholding bug-tracker technical detail (issues.chromium.org) until a majority of the Chrome user base has updated, to slow attacker reverse-engineering of the patch diff. The update is rolling out gradually over Stable and Extended Stable channels for Windows, macOS, and Linux, plus Chrome for Android.

Credited researchers include Google's own internal security team, Microsoft researcher xinchaotian, and independent researcher Salvatore Gulizia; several credits remain unpublished (marked TBD by Google) and bug-bounty reward amounts have not yet been disclosed. Because Chrome/Chromium underpins a wide range of downstream browsers (Microsoft Edge, Brave, Opera, Vivaldi and other Chromium-based products), the fixed defects are expected to propagate into corresponding downstream security advisories in the days following this release.

MITRE ATT&CK techniques used in TL-2026-1368

Collection

T1005 Data from Local System

Execution

T1059.007 JavaScript; T1203 Exploitation for Client Execution; T1204.001 Malicious Link; T1204.002 Malicious File

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Discovery

T1082 System Information Discovery

Initial Access

T1189 Drive-by Compromise; T1566.002 Spearphishing Link

Defense Evasion

T1211 Exploitation for Stealth; T1620 Reflective Code Loading

Resource Development

T1587.004 Exploits; T1588.005 Exploits

Reconnaissance

T1592.002 Software; T1595.002 Vulnerability Scanning

Affected products and versions in Chrome 150 Security Update Fixes 15 Vulnerabilities

  • Google — Chrome (Windows)
    Vulnerable versions: prior to 150.0.7871.124/.125
    Fixed in: 150.0.7871.124/.125
  • Google — Chrome (macOS)
    Vulnerable versions: prior to 150.0.7871.124/.125
    Fixed in: 150.0.7871.124/.125
  • Google — Chrome (Linux)
    Vulnerable versions: prior to 150.0.7871.124
    Fixed in: 150.0.7871.124
  • Google — Chrome (Android)
    Vulnerable versions: prior to 150.0.7871.124
    Fixed in: 150.0.7871.124
  • Chromium Project — Chromium open-source browser engine
    Vulnerable versions: branches prior to the 150 stable cut
    Fixed in: 150 stable branch and later

Remediation for Chrome 150 Security Update Fixes 15 Vulnerabilities

Patches

  • Chrome 150.0.7871.124/.125 (Windows, macOS)
  • Chrome 150.0.7871.124 (Linux, Android)

Immediate actions

  • Update Google Chrome to 150.0.7871.124/.125 (Windows/macOS) or 150.0.7871.124 (Linux, Android) via chrome://settings/help
  • Restart the browser after update to fully apply the patched renderer/V8/GPU binaries
  • Force-push the Chrome update via enterprise management (Chrome Browser Cloud Management, Google Admin console, or GPO) rather than waiting for the default gradual rollout
  • Update any Chromium-based downstream browsers (Microsoft Edge, Brave, Opera, Vivaldi) once their corresponding security advisories ship

Workarounds

  • No effective workaround short of patching; disabling JavaScript/Canvas or restricting video playback reduces but does not eliminate individual attack surfaces (V8, HTML-in-Canvas, libyuv) while leaving Ozone UAF paths exposed

Longer-term hardening

  • Enable Site Isolation and ensure renderer sandboxing policies remain enforced in managed Chrome deployments
  • Track Chromium security release notes and CVE feeds for recurring UAF/type-confusion classes in Ozone, V8, and Skia to prioritize patch cadence
  • Restrict or monitor untrusted video/HTML content ingestion paths (e.g., email gateways, web proxies) that could deliver crafted trigger files for libyuv/V8 bugs
  • Maintain endpoint detection coverage for renderer-process crash-then-respawn patterns consistent with failed or successful UAF exploitation attempts

CVEs associated with Chrome 150 Security Update Fixes 15 Vulnerabilities

  • CVE-2026-15764
  • CVE-2026-15765
  • CVE-2026-15766
  • CVE-2026-15767
  • CVE-2026-15768
  • CVE-2026-15769
  • CVE-2026-15770
  • CVE-2026-15771
  • CVE-2026-15772
  • CVE-2026-15773
  • CVE-2026-15774
  • CVE-2026-15775
  • CVE-2026-15776
  • CVE-2026-15777
  • CVE-2026-15778

Weaknesses (CWE) in Chrome 150 Security Update Fixes 15 Vulnerabilities

CWE-416, CWE-457, CWE-843, CWE-122

Timeline of Chrome 150 Security Update Fixes 15 Vulnerabilities

  • CVE-2026-15764 (Ozone use-after-free) reported to Google's Chrome security team via the Chromium issue tracker.
  • CVE-2026-15765, the second Critical Ozone use-after-free, reported via the Chromium issue tracker.
  • CVE-2026-15776, a V8 type-confusion bug enabling sandboxed arbitrary code execution, reported via the Chromium issue tracker.
  • Google publishes the Chrome 150 Stable Channel Update blog post on chromereleases.googleblog.com listing all 15 fixed CVEs.
  • Google states the update will continue rolling out over the coming days to weeks across managed and consumer channels.
  • Threat surfaced via Cyber Security News advisory coverage and ingested into the TL-Intel hunt pipeline.
  • Google Chrome for Android updated to 150.0.7871.124, closing the same set of vulnerabilities on the mobile platform.
  • Chrome 150.0.7871.124/.125 (Windows/macOS) and 150.0.7871.124 (Linux) begin gradual Stable and Extended Stable channel rollout.

Sources cited for Chrome 150 Security Update Fixes 15 Vulnerabilities

Threats related to Chrome 150 Security Update Fixes 15 Vulnerabilities

Detection coverage for TL-2026-1368

As of 2026-07-15, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1368 across Splunk SPL, Microsoft KQL and Sigma, covering 19 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats