Back to Feed
VulnerabilitiesJul 20, 2026

Chrome 150 Update Patches Severe Memory Safety Bugs

Chrome 150 patches seven memory safety bugs including critical use-after-free flaws.

Summary

Google released Chrome 150 to fix seven memory safety vulnerabilities, including three critical use-after-free flaws in CameraCapture, GPU, and Network components, and three high-severity issues in Cast, Ozone, and Aura. An additional out-of-bounds read/write in the V8 JavaScript engine was identified by OpenAI Codex Security. No active exploitation has been reported, but users are strongly advised to update immediately.

Full text

Google has released a Chrome 150 security update that resolves seven memory safety bugs, including critical and high-severity use-after-free vulnerabilities. The browser refresh patches three critical-severity use-after-free flaws impacting Chrome’s CameraCapture, GPU, and Network components. All three weaknesses were discovered by Google. Additionally, the update fixes three high-severity use-after-free issues in Cast, Ozone, and Aura; Google discovered these vulnerabilities as well. The seventh security defect is an out-of-bounds read and write flaw in the V8 JavaScript engine that was identified by OpenAI Codex Security. Google has yet to determine the bug bounty amount to be paid for the finding. Google makes no mention of any of these security defects being exploited in the wild, but users are advised to update their browsers as soon as possible, as threat actors have targeted memory safety issues in Chrome. For years, the internet giant has been hardening the browser against the exploitation of memory safety bugs, including by transitioning to memory-safe programming languages such as Rust.Advertisement. Scroll to continue reading. Since April, the internet giant has patched over 1,400 Chrome vulnerabilities, including hundreds of memory safety flaws, most of which were discovered by Google, likely through the use of AI. The latest Chrome iteration is now rolling out as versions 150.0.7871.128/.129 for Windows and macOS and as version 150.0.7871.128 for Linux. Related: Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates Related: WP2Shell WordPress Vulnerabilities Exploited in the Wild Related: Fresh SharePoint Vulnerability Exploited Soon After Disclosure Related: Legacy Systems, Real-World Impacts: The Reality of OT Security Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Fresh SharePoint Vulnerability Exploited Soon After DisclosureCoca-Cola Suspends US Fairlife Production Due to Ransomware AttackOak Emerges From Stealth Mode With $60 Million in FundingSplunk, Zoom Patch Critical VulnerabilitiesF5 Patches Multiple NGINX, BIG-IP VulnerabilitiesOld UEFI Shims Expose Systems to Secure Boot BypassNightmare Eclipse Drops ‘LegacyHive’ Windows Zero-Day Unpatched Cursor Vulnerability Exposes Users to Code Execution Latest News Hugging Face Hacked in Autonomous AI AttackWP2Shell WordPress Vulnerabilities Exploited in the WildIn Other News: Iran Tracks US Military Phones, CrashStealer macOS Malware, CVD BlueprintPodcast: Broken Governance, Agentic AI, and the MindStone Agent ExclusiveBeacon Security Raises $13 Million for Security Data PlatformIndustry Reactions to Pentagon Suspending CMMC Phase 2: Feedback FridayCyberattack Disrupts Operations of Japanese Frozen Food Giant NichireiRisk Ledger Raises $32 Million in Series B Funding Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Why Email Security Keeps Failing (And What Has to Change) July 8, 2026 Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more. Register Virtual Event: 2026 Cloud Security Summit July 15, 2026 This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments. Register People on the MoveJazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO.AJ Shipley has been appointed Chief Product Officer at CrowdStrike.Brinqa has named Ron Dovich as Chief AI and Automation Officer, David Allen as CTO, Steve Biagioni as CFO, and James Walta as VP of Product.More People On The MoveExpert Insights Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) The Shift Toward Business-Aligned Risk Management Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin) How to Conduct a Successful Audit of AI-Driven Software Development As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou) Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors From model selection and automation to validation and measurable results, the right questions can help enterprises separate genuine AI capabilities from marketing hype. (Joshua Goldfarb) The AI Token Costs That Can Break Cybersecurity As cybersecurity platforms embrace agentic AI, organizations must balance detection performance against the escalating costs of token consumption, deployment architecture, and AI credits. (Danelle Au) Flipboard Reddit Whatsapp Whatsapp Email

Entities

Google (vendor)Chrome (product)V8 (product)OpenAI (vendor)Rust (technology)