// NEXUSVOID CYBER NEWS

<- ALL CYBER NEWS

High

Chrome, Chrome 150, use-after-free, memory safety, V8, browser security, patch

Chrome 150 Update Patches 7 Memory-Safety Bugs

The Chrome 150 update patches 7 memory-safety bugs — 3 critical use-after-free flaws in GPU, Network, and CameraCapture. Update to 150.0.7871.128 now.

The Chrome 150 update fixes seven memory-safety vulnerabilities — three of them critical use-after-free flaws in the GPU, Network, and CameraCapture components — that could let a malicious web page corrupt memory and potentially run code. No in-the-wild exploitation is confirmed, but Chrome memory bugs are a favorite target, so update to 150.0.7871.128/129 now.

What happened. Google shipped Chrome 150 with fixes for seven vulnerabilities: three critical-severity use-after-free flaws (in CameraCapture, GPU, and Network), three high-severity use-after-free issues (in Cast, Ozone, and Aura), and one out-of-bounds read/write flaw in the V8 JavaScript engine. Google's own researchers found six; the seventh, in V8, was discovered by OpenAI Codex Security — an AI system — and Google has not yet set the bug-bounty amount. Use-after-free bugs in the browser's rendering and GPU paths are the classic building block for drive-by exploitation.

Is the Chrome 150 update being exploited?

No in-the-wild exploitation has been confirmed for these specific bugs, and Google has not flagged any as a zero-day. That said, Google itself notes that threat actors have repeatedly targeted memory-safety issues in Chrome, and use-after-free flaws in GPU and Network are exactly the class that gets weaponized after patch details emerge. Treat this as urgent even without a KEV listing.

Which Chrome versions are patched?

Platform

Patched version

Windows / macOS

150.0.7871.128 / .129

Linux

150.0.7871.128

Chromium-based browsers (Edge, Brave, Opera, Vivaldi) inherit the same fixes — update those once their vendors ship the rebuild.

How do I update Chrome?

  • Open Settings → About Chrome (or chrome://settings/help); Chrome downloads the update automatically.

  • Relaunch the browser to apply it — an update is not active until you restart.

  • For managed fleets, confirm the patched build rolls out and enforce a restart.

Who's affected. Every Chrome user on Windows, macOS, or Linux running a build below 150.0.7871.128, plus users of Chromium-based browsers until their vendors ship the fix.

Our read. The detail worth pausing on is who found the V8 bug: an AI security agent, OpenAI Codex Security, surfaced a flaw that shipped to billions of users. Machine-speed discovery cuts both ways — the same capability that helps Google find bugs helps adversaries find and weaponize them faster, compressing the safe patch window. Browsers are the endpoint most exposed to hostile input on Earth; assuming "we'll patch at the next cycle" is the gap. Verifying that your fleet is actually on the fixed build — not just that a policy exists — is the control that closes it.

Reporting by SecurityWeek; component and version detail per Google's Chrome release notes. Sources linked above. Related: our continuous verification approach.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.