VORANT. Threat Intelligence Sign in Get the full feed

Google Chrome Patches 14 Vulnerabilities

medium vulnerability

Google patched 14 Chrome vulnerabilities, including several use-after-free and type confusion bugs, that could allow arbitrary code execution.

Google has released Chrome version 150.0.7871.124/.125 to address 14 vulnerabilities affecting Windows, Mac, and Linux platforms. The flaws span multiple components including Ozone, Skia, libyuv, V8, GPU, Core, UI, Media, and Navigation, with root causes including use-after-free conditions, uninitialized memory use, heap buffer overflow, type confusion, and insufficient input/policy validation. The most severe of these vulnerabilities could allow an attacker to achieve arbitrary code execution in the context of the logged-on user.

Exploitation would typically occur via a drive-by compromise, where a user visits a malicious or compromised webpage that triggers one of the memory-corruption or logic flaws. Depending on the privileges of the logged-in user, successful exploitation could enable installation of programs, data manipulation, or creation of new accounts with full rights. MS-ISAC notes there are no current reports of in-the-wild exploitation for these specific CVEs.

Organizations are advised to apply Google's updates promptly following testing, enforce least-privilege principles, enable anti-exploitation features (DEP, WDEG, SIP/Gatekeeper), and maintain web/DNS filtering and user awareness training to reduce exposure to drive-by compromise vectors.

Mentioned in this report

Vulnerabilities CVE-2026-15764CVE-2026-15765CVE-2026-15766CVE-2026-15767CVE-2026-15768CVE-2026-15769CVE-2026-15770CVE-2026-15771CVE-2026-15772CVE-2026-15773CVE-2026-15774CVE-2026-15775CVE-2026-15776CVE-2026-15777CVE-2026-15778

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-069

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free