Google released a Chrome 150 Stable security update that patches 27 vulnerabilities, including two critical use-after-free flaws that could lead to remote code execution if a user visits a malicious webpage. The most severe issues are CVE-2026-15112 in Chrome’s Ozone platform abstraction layer and CVE-2026-15129 in the Views UI framework. Patched versions are 150.0.7871.114/.115 for Windows and macOS and 150.0.7871.114 for Linux.
The update also fixes 13 use-after-free bugs overall, along with integer overflow, out-of-bounds access, uninitialized use, and insufficient validation issues affecting components including V8, ANGLE, Autofill, WebRTC, Codecs, Extensions, Forms, Payments, and Navigation. Google said most flaws were found internally, with only three reported externally for a combined $3,000 in bug bounty rewards, and said there is no indication of active exploitation, though the volume of memory-safety defects raises the risk of weaponization.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Google rolled out Chrome 150 for Android, adding a dedicated back button in the overflow menu and shipping the same 27 security fixes as the corresponding desktop Chrome 150 releases unless otherwise noted. The update includes fixes for two critical use-after-free flaws, CVE-2026-15112 in Ozone and CVE-2026-15129 in Views.
Google released a Chrome 150 Stable security update that patches 27 vulnerabilities, including two critical use-after-free flaws in the Ozone and Views components. The update brings Chrome to version 150.0.7871.114/.115 on Windows and macOS and 150.0.7871.114 on Linux.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
techrepublic.com
Open sourcemalwarebytes.com
Open sourcecyber.gc.ca
Open sourcecybersecuritynews.com
Open sourcesecurityweek.com
Open sourcechromereleases.googleblog.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.