Description
Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted Chrome Extension. (Chromium security severity: High)
Published: 2026-07-08
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow in the Chrome Extensions API allows an attacker, who has convinced a user to install a malicious extension, to read memory outside the intended bounds. The vulnerability is identified as CWE‑190 and can lead to data leakage from the victim’s browser process. The official severity is high in Chromium’s internal ranking.

Affected Systems

All desktop installations of Google Chrome with a version number lower than 150.0.7871.115 are affected. The flaw exists in the extensions handling code across all common platforms (Windows, macOS, Linux). Any installed extension that accesses the vulnerable API is capable of triggering the overflow.

Risk and Exploitability

The CVSS score is 4.3, indicating moderate severity. The EPSS score is lower than 1%, evidencing that exploitation probability is low. The vulnerability is not listed in CISA’s KEV catalog. The attack requires a user to install a malicious extension, which limits the vector to social engineering. Nonetheless, once in place, the extension can perform out‑of‑bounds reads that could expose application‑level data.

Generated by OpenCVE AI on July 26, 2026 at 16:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Chrome update to version 150.0.7871.115 or newer
  • Configure the Chrome enterprise policy to block installation of unverified extensions
  • Remove all extensions that were installed before the update date until they are verified safe

Generated by OpenCVE AI on July 26, 2026 at 16:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4677-1 chromium security update
Debian DSA Debian DSA DSA-6387-1 chromium security update
History

Fri, 24 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chrome Extensions API

Tue, 21 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chrome Extensions API

Fri, 17 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chrome Extensions API Allows Out-of-bounds Memory Read

Wed, 15 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chrome Extensions API Allows Out-of-bounds Memory Read

Mon, 13 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Memory Read via Chrome Extension from Integer Overflow

Sun, 12 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Memory Read via Chrome Extension from Integer Overflow

Fri, 10 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Out‑Bound Memory Read via Extension API Integer Overflow

Fri, 10 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Out‑Bound Memory Read via Extension API Integer Overflow

Thu, 09 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 08 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Description Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted Chrome Extension. (Chromium security severity: High)
Weaknesses CWE-190
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-09T10:36:37.839Z

Reserved: 2026-07-08T17:07:38.340Z

Link: CVE-2026-15108

cve-icon Vulnrichment

Updated: 2026-07-09T10:36:31.758Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T16:30:06Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound