News·3 min read

Google Chrome Update Fixes 15 Security Flaws, Including Critical Ozone UAF Flaws

Google has rolled out a new Chrome Stable channel update addressing 15 security vulnerabilities, including two critical-severity use-after-free (UAF) flaws in the Ozone platform layer. The update brin

CS
CyberShield Team
2026-07-15
Share:
Google Chrome Update Fixes 15 Security Flaws, Including Critical Ozone UAF Flaws

Google has rolled out a new Chrome Stable channel update addressing 15 security vulnerabilities, including two critical-severity use-after-free (UAF) flaws in the Ozone platform layer. The update brings Chrome to version 150.0.7871.124/.125 for Windows and Mac, and 150.0.7871.124 for Linux, with the rollout expected to continue over the coming days and weeks. Google Chrome Update […] The post Google Chrome Update Fixes 15 Security Flaws, Including Critical Ozone UAF Flaws appeared first on Cyber Security News.

Google has rolled out a new Chrome Stable channel update addressing 15 security vulnerabilities, including two critical-severity use-after-free (UAF) flaws in the Ozone platform layer. The update brings Chrome to version 150.0.7871.124/.125 for Windows and Mac, and 150.0.7871.124 for Linux, with the rollout expected to continue over the coming days and weeks. Google Chrome Update Fixes 15 Security Flaws The most severe issues patched in this release are CVE-2026-15764 and CVE-2026-15765, both use-after-free vulnerabilities in Ozone, Chrome’s abstraction layer for platform-specific windowing and graphics operations. Use-after-free bugs in Ozone are particularly dangerous because they can lead to memory corruption, potentially enabling attackers to achieve remote code execution or sandbox escape if exploited alongside other vulnerabilities. High-Severity Fixes The update also resolves 12 high-severity vulnerabilities spanning multiple Chrome components: CVE IDVulnerability TypeAffected ComponentCVE-2026-15766Uninitialized useSkia (graphics rendering)CVE-2026-15767Heap buffer overflowlibyuv (video processing)CVE-2026-15768Insufficient policy enforcementHTML-in-CanvasCVE-2026-15769Insufficient input validationLinux Toolkit ThemingCVE-2026-15770Uninitialized useV8 (JavaScript engine)CVE-2026-15771Insufficient validationMedia handlingCVE-2026-15772Use-after-freeGPU processingCVE-2026-15773Use-after-freeCoreCVE-2026-15774Use-after-freeSkiaCVE-2026-15775Insufficient policy enforcementV8CVE-2026-15776Type confusionV8CVE-2026-15777Use-after-freeUI components Notably, V8 accounts for three separate high-severity fixes in this release, underscoring the JavaScript engine’s continued status as a high-value target for exploit development. A single medium-severity flaw, CVE-2026-15778, involving insufficient validation in Chrome’s Navigation component, rounds out the disclosure list. Use-after-free and type confusion vulnerabilities remain among the most exploited bug classes in browser security, frequently forming the backbone of exploit chains used in targeted attacks and drive-by compromise campaigns. Google continues to withhold technical details and bug links for several entries until a majority of users receive the patched build, a standard practice to prevent active exploitation before adoption reaches critical mass. Mitigation According to Google’s advisory, users should verify that their Chrome installation has been updated to version 150.0.7871.124/.125 by navigating to Settings > About Chrome, then restarting the browser to apply the patch. Given the presence of critical UAF flaws in Ozone, delaying this update leaves systems exposed to potential memory corruption exploits. Give your SOC the intelligence it needs to act with confidence. Explore ANY.RUN Threat Intelligence Feeds to reduce noise and improve operational efficiency. The post Google Chrome Update Fixes 15 Security Flaws, Including Critical Ozone UAF Flaws appeared first on Cyber Security News.

Share:

Join the Discussion

Comments coming soon. Follow us on social media for real-time discussions.