Junglewise Threat Intelligence

CVE-2026-15904: Google Chrome use after free in Ozone

CVE-2026-15904 · Severity: info · Published 2026-07-20

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Linux could allow a remote attacker to compromise a user's system. By tricking a user into visiting a malicious website and performing specific mouse or keyboard actions, an attacker could cause the browser to crash or execute unauthorized code. This could lead to the theft of sensitive data or unauthorized access to the user's computer.

Technical details

A use-after-free (UAF) vulnerability exists in the Ozone component of Google Chrome for Linux. Ozone is the platform abstraction layer used by Chromium for input and graphics. The flaw is triggered when a remote attacker convinces a user to visit a specially crafted HTML page and perform specific UI gestures, leading to memory corruption in the heap. This could potentially result in arbitrary code execution within the browser's sandbox. The issue was addressed in version 150.0.7871.128.

Affected products

  • Google Chrome prior to 150.0.7871.128

Timeline

  • 2026-07-09: other: Reported to Google
  • 2026-07-16: patched: Stable channel update released
  • 2026-07-20: advisory: NVD publication date

References

Related threats