Google released an unscheduled update for the web browser Chrome on Friday night. It is the second update this week after the scheduled update on Wednesday. The update also addresses critical security vulnerabilities.

According to the version announcement in the Chrome Release Blog, the developers are now closing seven more security vulnerabilities in the web browser. Three of them are considered “critical”, involving unspecified use-after-free vulnerabilities in the CameraCapture (CVE-2026-15899), GPU (CVE-2026-15900), and Network (CVE-2026-15901) components. The four other vulnerabilities have been classified as “high” risk. It is not clear from the announcement why the update is happening outside of the schedule – if the vulnerabilities are being exploited by attackers on the internet, Google usually states this in the version announcement as well. This is not the case here.

The updated Chrome versions 150.0.7871.128 for Android and Linux, and 150.0.7871.128/.129 for macOS and Windows, therefore close the security holes.

Scheduled Chrome Update

On Wednesday night, Google's developers had closed 15 vulnerabilities in the browser, two of which were considered critical risks. Both were use-after-free vulnerabilities in the Ozone component. Here too, there were no indications of active exploitation of the fixed vulnerabilities in the wild. The versions from Wednesday that fix the vulnerabilities were 150.0.7871.124 for Linux and 150.0.7871.124/.125 for macOS and Windows. At the same time, Google also released the first 151 builds for Android and iOS.