Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity Vulnerabilities (CVE-2026-16413 through CVE-2026-16424)

Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity (TL-2026-1605), also tracked as Chrome 150.0.7871.181/.182 Stable Channel Security Update, is a high-severity software vulnerability, first published 2026-07-22. It has no confirmed attribution, affects Google Chrome (Windows), references 12 CVEs (CVE-2026-16413, CVE-2026-16414, CVE-2026-16415), maps to 17 MITRE ATT&CK techniques (T1055, T1068, T1071), and is covered by 9 detection rules and 28 indicators of compromise.

Key facts for TL-2026-1605

Threat ID
TL-2026-1605
Also known as
Chrome 150.0.7871.181/.182 Stable Channel Security Update
Severity
HIGH
Status
PATCHED
Category
VULNERABILITY
First published
2026-07-22
Last reviewed
2026-07-22
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
all-sectors, enterprise, consumer, government administration, education, technology
Target regions
Global
Detection rules
9
Indicators of compromise
28
Updates
2026-07-22 · revalidated 1× · latest source

Malware and tooling in Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity

Malware and tooling: AFL, AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, libFuzzer

Google shipped Chrome 150.0.7871.181/.182 (Windows/macOS/Linux) fixing 12 High-severity memory-safety and validation bugs across ANGLE, Chromecast, Extensions, Skia, V8, WebAudio, Certificate handling, UI, and GPU. No active exploitation was confirmed and the batch is not listed in the CISA KEV catalog; Google withheld technical details pending broader update adoption, per its standard disclosure policy.

How Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity works

On 2026-07-22, Google published a Chrome Stable channel security update raising the browser to version 150.0.7871.181/.182 on Windows and macOS, and 150.0.7871.181 on Linux. The release addresses 12 vulnerabilities, all rated High severity by the Chromium security team, spanning nine distinct components: ANGLE (2 bugs — CVE-2026-16413 out-of-bounds write, CVE-2026-16419 out-of-bounds read and write), Chromecast (2 bugs — CVE-2026-16414 insufficient validation of untrusted input, CVE-2026-16416 integer overflow, both requiring a local attacker on the network), Extensions (1 bug — CVE-2026-16415 insufficient validation of untrusted input), Skia (1 bug — CVE-2026-16417 uninitialized use), V8 (1 bug — CVE-2026-16418 stack buffer overflow enabling in-sandbox code execution), WebAudio (2 bugs — CVE-2026-16420 type confusion and CVE-2026-16421 inappropriate implementation, both enabling in-sandbox code execution via a crafted HTML page), Certificate handling on Linux (1 bug — CVE-2026-16422 insufficient validation enabling domain spoofing by an attacker in a privileged network position), UI (1 bug — CVE-2026-16423 use-after-free), and GPU on Android (1 bug — CVE-2026-16424 use-after-free enabling sandbox escape by an attacker who has already compromised the renderer process).

Ten of the twelve bugs were found and reported internally by Google's own security engineering and fuzzing infrastructure, which per Google's public tooling disclosures relies on AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, and AFL to surface memory-safety classes before external discovery. The remaining two — CVE-2026-16420 and CVE-2026-16421, both WebAudio bugs — were discovered and reported externally by XBOW, an autonomous AI-driven vulnerability-research system, and triaged by researcher Brendan Dolan-Gavitt; each report earned a $500 bounty under Chrome's Vulnerability Reward Program. This is notable as an early example of AI-agent-driven fuzzing/bug-hunting directly contributing disclosed CVEs to a mass-market browser, a trend expected to accelerate discovery of memory-safety classes (UAF, type confusion, OOB, stack overflow) that have historically dominated in-the-wild Chrome exploit chains.

The memory-corruption bugs (V8 stack buffer overflow, the two ANGLE OOB bugs, the GPU and UI use-after-frees, and the WebAudio type-confusion/inappropriate-implementation pair) are the highest-value entries for exploit development: V8 and ANGLE sit directly in the JavaScript-engine and GPU/graphics-abstraction attack surface that has historically anchored real-world Chrome sandbox-escape and remote-code-execution chains, and the GPU UAF on Android is described by the vendor as reachable by an attacker who has already compromised the renderer process — i.e., a second-stage bug suited for chaining after an initial renderer-process compromise (e.g., via the V8 or WebAudio bugs in this same batch) to escape the Chrome sandbox. The Extensions bug (CVE-2026-16415) and the Certificate-validation bug (CVE-2026-16422) round out the batch with input-validation and trust-control weaknesses rather than pure memory corruption: the former could allow a malicious or compromised extension update/input to be processed unsafely, while the latter allows an on-path/privileged-network-position attacker to spoof a domain to a Linux Chrome client by exploiting insufficient certificate validation — functionally an adversary-in-the-middle primitive.

Google has confirmed no in-the-wild exploitation of any of the 12 CVEs at time of disclosure, and none of the 12 identifiers appear in the CISA Known Exploited Vulnerabilities (KEV) catalog as of 2026-07-22. Consistent with Chromium's standard disclosure policy, Google restricted access to the underlying bug-tracker entries and did not publish PoC or technical root-cause detail, to slow reverse-engineering of the fixes into working exploits while the patched build rolls out to the broader user base over the following days/weeks. Defenders should treat this as a routine but high-volume patch-adoption and browser-fleet-hygiene event: 12 High-severity memory-safety fixes in a single release is an above-average batch size, and the historical base rate for silent 1-day weaponization of Chrome memory-corruption bugs (once technical details leak or are independently rediscovered) means enterprise patch cadence for Chrome/Chromium-based browsers (Edge, Brave, Opera, Vivaldi) should be prioritized accordingly.

MITRE ATT&CK techniques used in TL-2026-1605

Privilege Escalation

T1055 Process Injection; T1068 Exploitation for Privilege Escalation

Command and Control

T1071 Application Layer Protocol

Persistence

T1176 Software Extensions

Collection

T1185 Browser Session Hijacking

Initial Access

T1189 Drive-by Compromise; T1190 Exploit Public-Facing Application

Execution

T1203 Exploitation for Client Execution; T1204.001 Malicious Link

Defense Evasion

T1211 Exploitation for Stealth

Discovery

T1217 Browser Information Discovery

Impact

T1499 Endpoint Denial of Service

Credential Access

T1557 Adversary-in-the-Middle

Resource Development

T1583.001 Domains; T1588.005 Exploits

Reconnaissance

T1592 Gather Victim Host Information

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity

  • Google — Chrome (Windows)
    Vulnerable versions: < 150.0.7871.181
    Fixed in: 150.0.7871.181; 150.0.7871.182
  • Google — Chrome (macOS)
    Vulnerable versions: < 150.0.7871.181
    Fixed in: 150.0.7871.181; 150.0.7871.182
  • Google — Chrome (Linux)
    Vulnerable versions: < 150.0.7871.181
    Fixed in: 150.0.7871.181
  • Google — Chrome (Android)
    Vulnerable versions: < 150.0.7871.182
    Fixed in: 150.0.7871.182

Remediation for Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity

Patches

  • Chrome 150.0.7871.181/.182 (Windows, macOS)
  • Chrome 150.0.7871.181 (Linux)

Immediate actions

  • Update Google Chrome to 150.0.7871.181/.182 (Windows/macOS) or 150.0.7871.181 (Linux) via chrome://settings/help
  • Restart the browser after update to load the patched binary — an update download alone does not remediate an already-running process
  • Force-push the Chrome update fleet-wide via enterprise policy (Chrome Browser Cloud Management / Group Policy) rather than relying on background auto-update rollout timing
  • Apply the same patch cadence to Chromium-based browsers (Microsoft Edge, Brave, Opera, Vivaldi) once their respective upstream merges ship, since several of the fixed components (V8, ANGLE, Skia) are shared Chromium code

Workarounds

  • No viable workaround short of updating; disabling JavaScript, WebAudio, or hardware GPU acceleration would degrade the specific attack surfaces but is not a supported or complete mitigation and breaks normal browser functionality

Longer-term hardening

  • Enforce automatic browser updates via enterprise policy and monitor patch-compliance dashboards for Chrome version drift across the fleet
  • Enable Chrome Enhanced Safe Browsing and site-isolation hardening to reduce blast radius of renderer-process compromise
  • Track Chromium security release notes and the CISA KEV catalog for any post-disclosure escalation of these CVEs to confirmed in-the-wild exploitation
  • Maintain browser fuzzing/bug-bounty awareness for AI-driven vulnerability research (e.g., XBOW) as a growing source of rapid, low-cost memory-safety disclosures
  • Review enterprise extension allowlists/policies given the Extensions-component input-validation bug (CVE-2026-16415)
  • For Linux fleets, monitor certificate-validation behavior and consider network-layer TLS inspection controls to reduce exposure to the CVE-2026-16422 domain-spoofing class until patch adoption is confirmed

CVEs associated with Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity

CVE-2026-16413, CVE-2026-16414, CVE-2026-16415, CVE-2026-16416, CVE-2026-16417, CVE-2026-16418, CVE-2026-16419, CVE-2026-16420, CVE-2026-16421, CVE-2026-16422, CVE-2026-16423, CVE-2026-16424

Weaknesses (CWE) in Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity

CWE-787, CWE-20, CWE-190, CWE-457, CWE-121, CWE-125, CWE-843, CWE-1288, CWE-416

Timeline of Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity

  • Google internally identifies and reports CVE-2026-16413 (ANGLE out-of-bounds write) and CVE-2026-16414 (Chromecast insufficient input validation).
  • Google internally reports CVE-2026-16415, an insufficient-validation-of-untrusted-input bug in the Extensions component.
  • Google internally reports CVE-2026-16416, an integer overflow in Chromecast.
  • Google internally reports CVE-2026-16417, an uninitialized-use bug in Skia.
  • Google internally reports CVE-2026-16418, a stack buffer overflow in V8 enabling in-sandbox arbitrary code execution via a crafted HTML page.
  • Google internally reports CVE-2026-16419, an out-of-bounds read/write in ANGLE.
  • XBOW, an autonomous AI security-research system, reports CVE-2026-16420 and CVE-2026-16421 (WebAudio type confusion and inappropriate implementation); researcher Brendan Dolan-Gavitt triages the reports, and each earns a $500 Chrome VRP bounty.
  • Google publishes the Chrome Releases stable-channel-update-for-desktop blog post documenting the 150.0.7871.181/.182 release ahead of full rollout.
  • Google internally reports CVE-2026-16422, insufficient certificate validation on Linux enabling domain spoofing.
  • Google internally reports CVE-2026-16423 (UI use-after-free) and CVE-2026-16424 (GPU use-after-free on Android, enabling sandbox escape from an already-compromised renderer process).
  • Research confirms the public Chromium issue-tracker entries for the disclosed CVEs remain access-restricted, consistent with Google's standard practice of withholding bug detail until broad patch rollout completes.
  • HKCERT publishes a mirrored security bulletin for the same Chrome multiple-vulnerabilities advisory.
  • GovCERT.HK issues Security Alert A26-07-36 summarizing the 12 Chrome CVEs and urging users to update to 150.0.7871.181 or later.
  • None of the 12 CVEs appear in the CISA Known Exploited Vulnerabilities catalog at time of disclosure; Google confirms no observed in-the-wild exploitation.
  • GBHackers, Cybersecurity News, and Cyberpress publish coverage summarizing the 12-CVE patch batch and the AI-fuzzing (XBOW) provenance of two of the bugs.
  • Google publishes the Chrome 150.0.7871.181/.182 Stable channel update for Windows, macOS, and Linux, fixing all 12 High-severity CVEs; technical bug-tracker details remain access-restricted pending broader update rollout.

Update history for TL-2026-1605

Sources cited for Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity

Threats related to Google Chrome 150.0.7871.181/.182 Patches 12 High-Severity

Detection coverage for TL-2026-1605

As of 2026-07-22, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1605 across Splunk SPL, Microsoft KQL and Sigma, covering 28 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats