Google Patches 27 Chrome Flaws, Two Rated Critical
Chrome 150 arrives with fixes for a string of memory-related bugs, most of them found by Google's own engineers rather than outside researchers.

Key points
- Google released Chrome 150 on a Wednesday in July 2026, fixing 27 security flaws in total.
- Two of those flaws are rated critical, meaning attackers could use them to cause serious harm to affected machines.
- External researchers reported only 3 of the 27 bugs and received a combined $3,000 in rewards.
- Chrome 150 is available as version 150.0.7871.114/115 for Windows and macOS, and version 150.0.7871.114 for Linux.
Google has pushed out a security update for Chrome 150, fixing 27 vulnerabilities, including two it rates critical. Critical is the highest severity label Google applies, reserved for flaws that could let an attacker take meaningful control of a device without much help from the person sitting in front of it.
Both critical bugs are "use-after-free" errors, a class of memory flaw where a program keeps using memory it has already released, which can let attackers run their own code on the machine. One flaw sits in Chrome's Ozone component, which handles how the browser talks to the underlying operating system on Linux. The other is in Chrome's Views component, which manages the browser's visual interface elements. Google found both internally last month.
Across the full update, 13 of the 27 bugs are use-after-free flaws. Ten carry a high-severity rating. The others cover uninitialized use, integer overflow, out-of-bounds memory access, and insufficient input validation.
Should ordinary Chrome users worry?
Not if they update immediately. None of these vulnerabilities are reported as actively exploited right now. That window can close quickly once a patch is public, because sophisticated attackers study what was fixed and work backwards. We covered an in-the-wild Chrome exploit on 9 June 2026, and the pattern is consistent: unpatched browsers become targets fast.
Updating takes about two minutes. In Chrome, click the three-dot menu in the top-right corner, choose Help, then About Google Chrome. The browser checks for the update and applies it. A restart completes the job.
Google's been finding the vast majority of its own bugs for more than two months, almost certainly through automated AI-assisted code scanning. The result is more flaws caught and fixed but lower bounty payouts to outside researchers, since fewer outsiders are finding issues first. Since April, Google has fixed more than 1,400 Chrome vulnerabilities, with over 1,000 resolved in June and July alone. That pace is unprecedented in Chrome's history, and it shifts the security calculus: the attack surface shrinks faster, but the sheer volume of patches makes it harder for IT teams to assess what actually posed meaningful risk.
For businesses managing Chrome across a fleet of employee computers, this is a routine but urgent patch cycle. Push it through your device-management tools today.



