Google has released two Chrome security updates within 48 hours, patching 27 vulnerabilities including two critical use-after-free flaws that could allow attackers to compromise affected browsers. The updates push Chrome 150 to version 150.0.7871.114/.115 for Windows and macOS, and version 150.0.7871.114 for Linux.
The rapid-fire patches continue an aggressive security cadence that has seen Google fix over 1,400 Chrome vulnerabilities since April 2026, including hundreds of memory safety bugs.
Vulnerability Details
The two critical flaws are use-after-free (UAF) vulnerabilities in Chrome's Ozone and Views components. Both were discovered by Google's internal security team last month. Use-after-free bugs occur when a program continues to reference memory after it has been freed, which can lead to arbitrary code execution when exploited.
The Chrome 150 July update addresses:
| Severity | Count | Types |
|---|---|---|
| Critical | 2 | Use-after-free in Ozone and Views |
| High | 15 | Use-after-free (10), uninitialized use, integer overflow, out-of-bounds read, out-of-bounds write, insufficient validation, inappropriate implementation |
| Medium | 3 | Use-after-free (1), insufficient data validation, insufficient policy enforcement |
| Low | 7 | Various implementation issues |
Between the two updates, Chrome fixed 13 use-after-free defects total, making memory safety the dominant theme of this patch cycle.
Why Use-After-Free Matters to Developers
Use-after-free vulnerabilities are a class of memory corruption bugs that remain one of the most common serious security issues in C++ codebases. When an attacker can control the memory that replaces a freed allocation, they can craft a payload to hijack control flow and execute arbitrary code.
For web developers, the practical impact is clear: even if you write safe JavaScript, the browser engine beneath your application can be the attack surface. This is why Chrome's move toward memory-safe languages like Rust in specific components is strategically important, though the vast majority of Chrome remains C++.
Chrome's Security Trajectory
The July 11 update follows a pattern that has defined Chrome 150's lifecycle. Since April, Google has patched over 1,400 Chrome vulnerabilities, with June and July releases alone addressing more than 1,000 flaws. The broader Chrome 150 release patched 382 security issues including 15 critical-severity bugs.
Notably, Google's internal teams are discovering the vast majority of these issues. In the July 11 update, only 3 of the 27 resolved vulnerabilities were reported by external researchers, who received a combined $3,000 in bug bounty rewards. This trend has been ongoing for over two months and reflects Google's substantial investment in internal fuzzing, code auditing, and security tooling.
While this has led to lower bug bounty payouts for external researchers, it means far more vulnerabilities are being caught before attackers can exploit them.
How to Update
Chrome updates automatically in the background, but if you have not restarted your browser recently, you may still be running a vulnerable version:
- Click the three-dot menu (top-right corner)
- Go to Help > About Google Chrome
- Chrome will check for updates and download them automatically
- Click Relaunch to complete the update
Check that your version is at least 150.0.7871.114 on Linux or 150.0.7871.115 on Windows and macOS. The version number consists of four parts: major, minor, build, and patch. After the major release number (150), the build and patch numbers are the ones to watch for security updates.
Linux users should note the Linux build lags slightly behind at version 150.0.7871.114, missing the .115 increment that Windows and macOS received.
Frequently Asked Questions
Q: Are these vulnerabilities being actively exploited? A: Google has not reported any of these flaws as being actively exploited in the wild. Both critical bugs were discovered internally during code audits.
Q: Why are there so many Chrome updates lately? A: Google has been on an aggressive security push since April, fixing over 1,400 vulnerabilities. The high volume reflects both the complexity of the Chrome codebase and Google's investment in automated vulnerability discovery tools.
Q: Do I need to update if I use Chrome on Linux? A: Yes, all desktop platforms are affected. Update to version 150.0.7871.114 for Linux.
Q: What is a use-after-free vulnerability? A: It is a memory corruption bug where a program continues to use a memory pointer after the memory has been freed. Attackers can exploit this to execute arbitrary code.
Q: How does this compare to the Chrome 150 Whopper update? A: The Whopper update in late June patched 382 vulnerabilities including 15 critical. The July 11 updates are smaller follow-ups fixing 27 more flaws, showing the ongoing pattern of sustained security maintenance.
Key Takeaways
- Two Chrome updates in two days fix 27 vulnerabilities including 2 critical use-after-free flaws
- The critical bugs affect Chrome's Ozone and Views components
- Google has patched over 1,400 Chrome vulnerabilities since April 2026
- Only 3 of the 27 bugs were reported by external researchers
- All users should update to Chrome 150.0.7871.114/.115 immediately
- No active exploitation reported, but the attack surface remains significant
- Linux users should install the .114 build; Windows and macOS users get .115
Sources: SecurityWeek, Malwarebytes, Google Chrome Releases
Automated Transmission
This entry was synthesized and populated dynamically using native API integrations.