Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN747
_____________________________________________________________________


DATE                : 13/07/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Google Chrome versions prior to
                               150.0.7871.114/.115.
 
=====================================================================

https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-desktop_01162222768.html
_____________________________________________________________________



Stable Channel Update for Desktop
Wednesday, July 8, 2026

The Stable channel has been updated to 150.0.7871.114/.115 for Windows
and Mac and 150.0.7871.114 for Linux, which will roll out over the
coming days/weeks. A full list of changes in this build is available
in the Log

Security Fixes and Rewards

Note: Access to bug details and links may be kept restricted until a
majority of users are updated with a fix. We will also retain
restrictions if the bug exists in a third party library that other
projects similarly depend on, but haven’t yet fixed.


This update includes 27 security fixes. Please see the Chrome Security
 Page for more information.

[N/A][518006275] Critical CVE-2026-15112: Use after free in Ozone.
Reported by Google on 2026-05-29

[N/A][524045160] Critical CVE-2026-15129: Use after free in Views.
Reported by Google on 2026-06-15

[$500][527385397] High CVE-2026-15132: Uninitialized Use in V8.
Reported by Pierre Langlois from Arm on 2026-06-24

[$500][527406824] High CVE-2026-15133: Use after free in
InterestGroups. Reported by Jihyeon Jeong (Compsec Lab, Seoul
National University / Research Intern) on 2026-06-24

[N/A][515443146] High CVE-2026-15108: Integer overflow in Extensions
API. Reported by Google on 2026-05-21

[N/A][516899138] High CVE-2026-15109: Uninitialized Use in ANGLE.
Reported by Google on 2026-05-26

[N/A][516948486] High CVE-2026-15110: Use after free in Extensions.
Reported by Google on 2026-05-27

[N/A][517508651] High CVE-2026-15111: Use after free in Views.
Reported by Google on 2026-05-28

[N/A][520540744] High CVE-2026-15113: Use after free in Autofill.
Reported by Google on 2026-06-05

[N/A][520565945] High CVE-2026-15114: Out of bounds read and write
in Codecs. Reported by Google on 2026-06-06

[N/A][520576676] High CVE-2026-15115: Insufficient validation of
untrusted input in WebAppInstalls. Reported by Google on 2026-06-06

[N/A][522092013] High CVE-2026-15116: Use after free in Actor.
Reported by Google on 2026-06-10

[N/A][522568496] High CVE-2026-15117: Use after free in Payments.
Reported by Google on 2026-06-11

[N/A][523238265] High CVE-2026-15118: Use after free in Input.
Reported by Google on 2026-06-12

[N/A][523505418] High CVE-2026-15119: Inappropriate implementation
in GetUserMedia. Reported by Google on 2026-06-13

[N/A][523609602] High CVE-2026-15120: Use after free in Core.
Reported by Google on 2026-06-13

[N/A][523712556] High CVE-2026-15121: Use after free in WebRTC.
Reported by Google on 2026-06-14

[N/A][523717219] High CVE-2026-15122: Insufficient validation of
untrusted input in Codecs. Reported by Google on 2026-06-14

[N/A][523729553] High CVE-2026-15123: Insufficient data validation
in DOM. Reported by Google on 2026-06-14

[N/A][523735038] High CVE-2026-15124: Insufficient policy
enforcement in Passwords. Reported by Google on 2026-06-14

[N/A][523737685] High CVE-2026-15125: Inappropriate implementation
in Forms. Reported by Google on 2026-06-14

[N/A][523748081] High CVE-2026-15126: Use after free in Forms.
Reported by Google on 2026-06-14

[N/A][523752265] High CVE-2026-15127: Inappropriate implementation
in WebGL. Reported by Google on 2026-06-14

[N/A][523756329] High CVE-2026-15128: Inappropriate implementation
in Forms. Reported by Google on 2026-06-14

[N/A][526541544] High CVE-2026-15130: Insufficient policy
enforcement in Navigation. Reported by Google on 2026-06-22

[$2000][503553615] Medium CVE-2026-15107: Use after free in
IndexedDB. Reported by zh1x1an1221 of Ant Group Tianqiong
Security Lab on 2026-04-17

[N/A][526542464] Medium CVE-2026-15131: Insufficient data
validation in Navigation. Reported by Google on 2026-06-22


We would also like to thank all security researchers that worked
with us during the development cycle to prevent security bugs
from ever reaching the stable channel.


Many of our security bugs are detected using AddressSanitizer,
MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow
Integrity, libFuzzer, or AFL.

Interested in switching release channels? Find out how here.
If you find a new issue, please let us know by filing a bug.
The community help forum is also a great place to reach out
for help or learn about common issues.


Daniel Yip

Google Chrome


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




