Back to search

Google

Chrome

Google web browser with frequent stable-channel releases.

Current version
Last checked: 2026-07-21

150

Release date
June 30, 2026
Security status
25 high-severity CVEs tracked in the last 90 days. Current version not affected.

Source

endoflife.date

Public release notes are linked for the latest stored release.

Release history

See the latest published releases stored for this product.

Version Published Notes
150 2026-06-30 Release Notes
149 2026-06-02 Release Notes
148 2026-05-05 Release Notes
147 2026-04-07 Release Notes
146 2026-03-10 Release Notes

Vulnerability tracking

versionPing monitors CVEs for this product. Matching CVEs are listed below. We only display CVEs with a CVSS score of 7.0 or higher that were published within the last 90 days.

Affected status is inferred from published affected version ranges where available. Always verify against the vendor advisory before making production decisions.

CVE Severity Published Status Summary
CVE-2026-15905 HIGH (7.8) 2026-07-20 Current versionnot affected

Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)

Affected versions
  • From (including) 150.0.7871.128 - Up to (excluding) 150.0.7871.128
CVE-2026-15777 HIGH (7.5) 2026-07-14 Current versionnot affected

Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.125
CVE-2026-15776 HIGH (8.8) 2026-07-14 Current versionnot affected

Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.125
CVE-2026-15774 HIGH (8.3) 2026-07-14 Current versionnot affected

Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.125
CVE-2026-15773 CRITICAL (9.6) 2026-07-14 Current versionnot affected

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.125
CVE-2026-15772 HIGH (8.3) 2026-07-14 Current versionnot affected

Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.125
CVE-2026-15769 HIGH (8.3) 2026-07-14 Current versionnot affected

Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.125
CVE-2026-15767 HIGH (8.8) 2026-07-14 Current versionnot affected

Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.125
CVE-2026-15765 HIGH (7.5) 2026-07-14 Current versionnot affected

Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

Affected versions
  • Up to (excluding) 150.0.7871.125
CVE-2026-15764 HIGH (7.5) 2026-07-14 Current versionnot affected

Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

Affected versions
  • Up to (excluding) 150.0.7871.125
CVE-2026-15133 HIGH (8.8) 2026-07-08 Current versionnot affected

Use after free in InterestGroups in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.115
CVE-2026-15132 HIGH (8.8) 2026-07-08 Current versionnot affected

Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.115
CVE-2026-15129 HIGH (8.8) 2026-07-08 Current versionnot affected

Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

Affected versions
  • Up to (excluding) 150.0.7871.115
CVE-2026-15126 HIGH (8.8) 2026-07-08 Current versionnot affected

Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.115
CVE-2026-15125 HIGH (8.8) 2026-07-08 Current versionnot affected

Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.115
CVE-2026-15123 HIGH (8.8) 2026-07-08 Current versionnot affected

Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.115
CVE-2026-15122 HIGH (8.3) 2026-07-08 Current versionnot affected

Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.115
CVE-2026-15121 HIGH (8.8) 2026-07-08 Current versionnot affected

Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.115
CVE-2026-15120 HIGH (8.3) 2026-07-08 Current versionnot affected

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.115
CVE-2026-15119 HIGH (8.3) 2026-07-08 Current versionnot affected

Race in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.115
CVE-2026-15118 HIGH (8.8) 2026-07-08 Current versionnot affected

Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.115
CVE-2026-15117 HIGH (7.5) 2026-07-08 Current versionnot affected

Use after free in Payments in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.115
CVE-2026-15116 HIGH (8.8) 2026-07-08 Current versionnot affected

Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.115
CVE-2026-15114 HIGH (8.8) 2026-07-08 Current versionnot affected

Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.115
CVE-2026-15113 CRITICAL (9.6) 2026-07-08 Current versionnot affected

Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Affected versions
  • Up to (excluding) 150.0.7871.115