Chrome 150 Security Update Fixes 15 Vulnerabilities Including Two Critical Use-After-Free Flaws in Ozone (CVE-2026-15764, CVE-2026-15765) — Threadlinqs Intelligence
As of 2026-07-15, Chrome 150 Security Update Fixes 15 Vulnerabilities Including Two Critical Use-After-Free Flaws in Ozone (CVE-2026-15764, CVE-2026-15765) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 19 indicators of compromise.
Threat ID: TL-2026-1368 · Severity: CRITICAL · CVSS: 8.8 · Status: PATCHED · Category: VULNERABILITY
Google shipped Chrome 150 (150.0.7871.124/.125 on Windows/macOS, 150.0.7871.124 on Linux and Android) fixing 15 vulnerabilities, including two Critical-rated use-after-free bugs in the Ozone
On July 14-15, 2026 Google published the Chrome 150 Stable Channel update (150.0.7871.124/.125 for Windows and macOS, 150.0.7871.124 for Linux and Android), resolving 15 security defects reported by external and internal researchers. The two Critical-rated defects, CVE-2026-15764 and CVE-2026-15765, are both use-after-free (CWE-416) vulnerabilities in Ozone, the abstraction layer Chromium uses for platform-specific windowing, input, and graphics operations on Linux and other embedder platforms. NVD records both as CVSS 3.1 7.5 (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H) — Google's internal severity rubric rates them Critical because Ozone UAF corruption can be chained toward remote code execution or sandbox escape, materially higher than the raw CVSS base score reflects. Exploitation requires a remote attacker to convince the victim to interact with a crafted HTML page through specific UI gestures (drag, resize, or similar Ozone-routed input) that triggers the free, followed by a use of the dangling object to corrupt the heap.
The remaining 13 defects are High- or Medium-severity memory-safety and policy-enforcement bugs distributed across core rendering and scripting components: two additional use-after-free bugs (GPU process, Core), a heap buffer overflow in libyuv (CVE-2026-15767, CVSS 8.8, triggered via a crafted video file and capable of sandbox-contained arbitrary code execution), a V8 type-confusion bug (CVE-2026-15776, CWE-843, CVSS 8.8, allowing arbitrary code execution inside the renderer sandbox via a crafted HTML page), two uninitialized-memory-use information-disclosure bugs in Skia and V8 (CVE-2026-15766 and CVE-2026-15770, both CWE-457, CVSS 6.5, leaking process memory contents), insufficient policy-enforcement issues in HTML-in-Canvas and V8, an untrusted-input-validation flaw in Linux Toolkit Theming, an input-validation flaw in the Media component, an additional use-after-free in Skia, a use-after-free in UI components, and an insufficient-validation issue in Navigation rated Medium.
No public proof-of-concept or in-the-wild exploitation has been reported for any of the 15 CVEs as of publication, and none appear in the CISA Known Exploited Vulnerabilities catalog. Consistent with Chromium's standard disclosure practice, Google is withholding bug-tracker technical detail (issues.chromium.org) until a majority of the Chrome user base has updated, to slow attacker reverse-engineering of the patch diff. The update is rolling out gradually over Stable and Extended Stable channels for Windows, macOS, and Linux, plus Chrome for Android.
Credited researchers include Google's own internal security team, Microsoft researcher xinchaotian, and independent researcher Salvatore Gulizia; several credits remain unpublished (marked TBD by Google) and bug-bounty reward amounts have not yet been disclosed. Because Chrome/Chromium underpins a wide range of downstream browsers (Microsoft Edge, Brave, Opera, Vivaldi and other Chromium-based products), the fixed defects are expected to propagate into corresponding downstream security advisories in the days following this release.
Weaknesses (CWE)
CWE-416, CWE-457, CWE-843, CWE-122
Target sectors: all-sectors, government administration, finance, health, education, technology, retail
Target regions: global
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 19 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-15764, CVE-2026-15765, CVE-2026-15766, CVE-2026-15767, CVE-2026-15768, CVE-2026-15769, CVE-2026-15770, CVE-2026-15771, CVE-2026-15772, CVE-2026-15773, T1592.002, T1595.002, T1588.005, T1587.004, T1189, T1566.002, T1203, T1204.001, T1204.002, T1059.007