CVE-2026-15904

Google · Chrome

A use after free vulnerability in the Ozone component of Google Chrome on Linux allows a remote attacker to achieve heap corruption via a crafted HTML page.

Executive summary

A high-severity use after free vulnerability in Google Chrome on Linux could allow remote attackers to execute arbitrary code or corrupt system memory.

Vulnerability

This is a use after free vulnerability in the Ozone component. It requires an unauthenticated remote attacker to convince a user to perform specific UI gestures while interacting with a crafted HTML page to trigger heap corruption.

Business impact

With a CVSS score of 8.8, this vulnerability poses a severe threat to system security. Successful exploitation could lead to full system compromise, unauthorized data access, or denial of service, significantly impacting the stability and security posture of affected Linux workstations.

Remediation

Immediate Action: Update Google Chrome to version 150.0.7871.128 or later immediately.

Proactive Monitoring: Monitor endpoint logs for unusual browser crashes or unexpected process behavior that may indicate attempts to exploit heap memory.

Compensating Controls: Use browser-based security policies to restrict the execution of untrusted scripts and ensure that users are trained to avoid interacting with suspicious web content.

Exploitation status

Public Exploit Available: False

Analyst recommendation

The severity of this vulnerability necessitates immediate action. Organizations must ensure that all Linux-based instances of Google Chrome are updated to version 150.0.7871.128 to mitigate the risk of remote code execution and heap corruption.