Junglewise Threat Intelligence

CVE-2026-15112: Google Chrome use after free in Ozone

CVE-2026-15112 · Severity: info · Published 2026-07-08

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome's Ozone component, which handles input and graphics abstraction. By tricking a user into visiting a specially crafted website, an attacker could potentially crash the browser or execute unauthorized code on the user's computer. This could lead to the theft of sensitive data or a complete compromise of the user's browsing session.

Technical details

A use-after-free (UAF) vulnerability exists in the Ozone abstraction layer of Google Chrome. The flaw is triggered when the browser incorrectly manages memory lifecycle for objects within the Ozone component, which is responsible for input and windowing system integration. A remote attacker can exploit this by enticing a user to load a maliciously crafted HTML page, leading to heap corruption. This can result in a browser crash (denial of service) or potentially arbitrary code execution within the context of the browser process. The vulnerability is addressed in Google Chrome version 150.0.7871.115 for Windows and Mac, and 150.0.7871.114 for Linux.

Affected products

  • Google Chrome < 150.0.7871.115

Timeline

  • 2026-05-29: disclosed: Reported by Google internal researchers
  • 2026-07-08: patched: Fixed in Stable Channel Update 150.0.7871.114/.115
  • 2026-07-08: advisory

References

Related threats