Google has released a new Chrome Stable update that fixes 27 security vulnerabilities, including two critical flaws that could allow remote code execution (RCE) on affected systems.
The update, now rolling out globally, upgrades Chrome to version 150.0.7871.114/.115 on Windows and macOS, and 150.0.7871.114 on Linux.
The most severe issues addressed in this release are tracked as CVE-2026-15112 and CVE-2026-15129, both of which are categorized as critical use-after-free vulnerabilities.
The first flaw resides in Chrome’s Ozone platform abstraction layer, while the second affects the Views UI framework.
Use-after-free vulnerabilities occur when memory is accessed after it has been freed, often leading to memory corruption that attackers can exploit to execute arbitrary code.
In real-world scenarios, successful exploitation could allow a remote attacker to compromise a victim’s system simply by luring them to a malicious webpage.
Alongside these critical bugs, Google patched numerous high-severity vulnerabilities across multiple Chrome components.
These include memory-safety issues, such as use-after-free flaws in Autofill, WebRTC, Core, Input, Payments, and Forms, as well as uninitialized memory usage in V8 and ANGLE.
Chrome Update Patches 27 Vulnerabilities
Several vulnerabilities also stem from insufficient validation of untrusted input in components such as WebAppInstalls and Codecs, which could be exploited to trigger unexpected behavior or bypass security controls.
Notably, CVE-2026-15132 highlights an uninitialized use vulnerability in the V8 JavaScript engine, a critical component responsible for executing web scripts.
Attackers often target V8 due to its complexity and direct exposure to web content, making such flaws particularly valuable in exploit chains.
Another issue, CVE-2026-15108, involves an integer overflow in the Extensions API, which could allow malicious extensions or crafted inputs to compromise browser integrity.
Google also addressed multiple issues with logic and policy enforcement, including flaws in password management, navigation handling, and DOM validation.
These weaknesses may not directly lead to code execution. However, they can still be abused to weaken browser security boundaries or facilitate further exploitation.
As with most Chrome releases, technical details for many vulnerabilities remain restricted to prevent active exploitation before users have applied the update.
| CVE ID | Vulnerability Type | Affected Component | Severity |
|---|---|---|---|
| CVE-2026-15112 | Use-after-free | Ozone | Critical |
| CVE-2026-15129 | Use-after-free | Views | Critical |
| CVE-2026-15132 | Uninitialized use | V8 | High |
| CVE-2026-15133 | Use-after-free | InterestGroups | High |
| CVE-2026-15108 | Integer overflow | Extensions API | High |
| CVE-2026-15109 | Uninitialized use | ANGLE | High |
| CVE-2026-15110 | Use-after-free | Extensions | High |
| CVE-2026-15111 | Use-after-free | Views | High |
| CVE-2026-15113 | Use-after-free | Autofill | High |
| CVE-2026-15114 | Out-of-bounds read/write | Codecs | High |
| CVE-2026-15115 | Insufficient input validation | WebAppInstalls | High |
| CVE-2026-15116 | Use-after-free | Actor | High |
| CVE-2026-15117 | Use-after-free | Payments | High |
| CVE-2026-15118 | Use-after-free | Input | High |
| CVE-2026-15119 | Inappropriate implementation | GetUserMedia | High |
| CVE-2026-15120 | Use-after-free | Core | High |
| CVE-2026-15121 | Use-after-free | WebRTC | High |
| CVE-2026-15122 | Insufficient input validation | Codecs | High |
| CVE-2026-15123 | Insufficient data validation | DOM | High |
| CVE-2026-15124 | Insufficient policy enforcement | Passwords | High |
| CVE-2026-15125 | Inappropriate implementation | Forms | High |
| CVE-2026-15126 | Use-after-free | Forms | High |
| CVE-2026-15127 | Inappropriate implementation | WebGL | High |
| CVE-2026-15128 | Inappropriate implementation | Forms | High |
| CVE-2026-15130 | Insufficient policy enforcement | Navigation | High |
| CVE-2026-15107 | Use-after-free | IndexedDB | Medium |
| CVE-2026-15131 | Insufficient data validation | Navigation | Medium |
Google confirmed that some bugs were identified internally using advanced fuzzing and memory analysis tools such as AddressSanitizer, libFuzzer, and Control Flow Integrity mechanisms, highlighting the continued importance of automated security testing in modern browser development.
While there is no indication that these vulnerabilities are being actively exploited in the wild, the presence of multiple memory corruption issues significantly increases the risk of weaponization.
Threat actors frequently chain such flaws with sandbox escape techniques to achieve full system compromise. Users are strongly advised to update Chrome immediately to the latest version to mitigate potential risks.
The update will be automatically applied over the coming days. However, users can manually trigger it by navigating to Chrome’s settings and checking for updates.
This release underscores the ongoing security challenges of maintaining a complex browser ecosystem, where even minor memory-handling errors can have severe consequences if left unpatched.
Stop Accepting SLAs Written for 2019 SOCs – Here’s the 2026 AI SLA Vendor Checklist – Download Free AI SOC SLA Guide