Junglewise Threat Intelligence

CVE-2026-15764: Google Chrome use after free in Ozone

CVE-2026-15764 · Severity: high · CVSS 7.5 · Published 2026-07-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome for Linux that could allow a remote attacker to compromise a user's computer. By tricking a user into visiting a malicious website and performing specific mouse or keyboard actions, an attacker could potentially crash the browser or execute unauthorized code. This could lead to the theft of sensitive information or full control over the affected system.

Technical details

A use-after-free (UAF) vulnerability exists in the Ozone abstraction layer of Google Chrome for Linux. The flaw is triggered when a remote attacker convinces a user to engage in specific UI gestures while visiting a specially crafted HTML page. This interaction leads to memory corruption in the heap, which can be leveraged for arbitrary code execution or a denial-of-service (browser crash). The vulnerability is addressed in Google Chrome version 150.0.7871.125.

Affected products

  • Google Chrome prior to 150.0.7871.125

Timeline

  • 2026-05-27: disclosed: Reported by Google internally
  • 2026-07-14: patched: Fixed in stable channel update 150.0.7871.125
  • 2026-07-14: advisory

References

Related threats