Vulnerabilities

Chrome 150 Update Patches 27 Vulnerabilities

The security refresh resolves 13 use-after-free bugs, including two critical-severity flaws found by Google.

Chrome security

Google on Wednesday announced a Chrome 150 security update that resolves 27 vulnerabilities, including two critical-severity flaws.

The two critical bugs are use-after-free issues in Chrome’s Ozone and Views components. Both were found by Google last month.

The Chrome refresh resolves a total of 13 use-after-free defects, including 10 high-severity and one medium-severity weakness.

Other types of vulnerabilities patched in this update include uninitialized use, integer overflow, out-of-bounds read and write, insufficient validation of untrusted input, inappropriate implementation, insufficient data validation, and insufficient policy enforcement.

Most of these flaws were discovered by Google, a trend that has been ongoing for over two months. Per Google’s advisory, only three of the newly resolved security defects were reported by external researchers, who received a total of $3,000 in bug bounty rewards.

Likely driven by the use of AI, the trend led to lower bug bounty rewards but resulted in far more security weaknesses being addressed.

Advertisement. Scroll to continue reading.

Since April, Google has rolled out fixes for more than 1,400 Chrome vulnerabilities, including hundreds of memory safety bugs. Chrome updates released in June and July resolved over 1,000 flaws.

The latest Chrome iteration is now available for download as versions 150.0.7871.114/.115 for Windows and macOS, and as version 150.0.7871.114 for Linux.

Related: Google Patches 382 Chrome Vulnerabilities

Related: Chrome 149 Update Resolves 18 Severe Vulnerabilities

Related: Unpatched Backdoor in Tenda Firmware Grants Admin Access to Devices

Related: CISA Urges Immediate Patching of Exploited ColdFusion, Langflow, Joomla Flaws

Related Content

Vulnerabilities

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE).

Artificial Intelligence

The internet giant has built an agent harness to find vulnerabilities across Chrome’s codebase.

Vulnerabilities

Tracked as CVE-2026-63077, the security defect can be exploited without authentication via the agent polling protocol.

Artificial Intelligence

Unauthenticated attackers could send HTTP requests to an exposed endpoint to execute commands inside the MCP bridge container.

Vulnerabilities

The major browser update resolves roughly 80 critical- and high-severity security defects.

Vulnerabilities

The vulnerability tracked as CVE-2026-20316 can be exploited by a remote, unauthenticated attacker to log into affected devices. 

Vulnerabilities

A total of five vulnerabilities have been patched in VMware ESXi, vCenter, Workstation, and Fusion.

Artificial Intelligence

The OpenAI models targeted services beyond Hugging Face as they attempted to solve the tasks they were given.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version