Google shipped a Chrome 150 security update Wednesday, fixing 27 vulnerabilities. Two of them are critical.
Both critical bugs are use-after-free issues — one in Chrome’s Ozone component, the other in Views. Google’s own security team found them last month.
All told, this update fixes 13 use-after-free defects. Ten of those are rated high severity, one is medium. The rest covers a grab bag of bug types: uninitialized use, integer overflow, out-of-bounds reads and writes, insufficient validation, inappropriate implementation, and more.
Google found most of these itself. Only three were reported by external researchers, who split a total of $3,000 in bug bounties. That’s low by Chrome standards, but it’s part of a trend. Google has been finding the vast majority of its own Chrome bugs lately, likely driven by AI-assisted fuzzing and testing.
Since April, Google has patched over 1,400 Chrome vulnerabilities. June and July alone accounted for more than 1,000. The pace is staggering.
The latest version is 150.0.7871.114/.115 for Windows and macOS, and 150.0.7871.114 for Linux. Chrome updates automatically, but a manual restart may be needed to apply the patch.
