Description
Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-08
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw present in Google Chrome’s Core rendering engine on Windows allows an attacker who has already compromised the renderer process to escape the browser sandbox. The vulnerability, identified as CWE‑416, could let malicious code gain privileges beyond the renderer, potentially leading to arbitrary code execution on the host. Chromium labels this flaw as high severity.

Affected Systems

Google Chrome for Windows versions prior to 150.0.7871.115 are affected. The issue does not impact other operating systems or Chrome releases newer than the stated version.

Risk and Exploitability

The EPSS score is < 1%, indicating a low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a pre‑existing compromise of the renderer process and delivery of a crafted HTML page. If an attacker can attain the renderer, the bug could be used to escape the sandbox and gain local privilege escalation. No publicly known exploit has been disclosed, so monitoring and prompt patching remain the best approach. The CVSS score of 8.3 indicates a high severity.

Generated by OpenCVE AI on July 23, 2026 at 10:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Chrome version 150.0.7871.115 or newer
  • Confirm with sandboxing enabled and that no sandbox violations are reported
  • Apply user‑level security policies that restrict rendering untrusted HTML from external origins

Generated by OpenCVE AI on July 23, 2026 at 10:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4677-1 chromium security update
Debian DSA Debian DSA DSA-6387-1 chromium security update
History

Thu, 23 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Renderer Enables Sandbox Escape

Thu, 16 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome Core Rendering Engine on Windows Leading to Sandbox Escape

Wed, 15 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome Core Rendering Engine on Windows Leading to Sandbox Escape

Mon, 13 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Renderer Allows Sandbox Escape on Windows

Sun, 12 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Renderer Allows Sandbox Escape on Windows

Sat, 11 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Core Enables Sandbox Escape on Windows

Fri, 10 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Core Enables Sandbox Escape on Windows

Thu, 09 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Use After Free Allowing Sandbox Escape via Crafted HTML in Google Chrome for Windows

Thu, 09 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Use After Free Allowing Sandbox Escape via Crafted HTML in Google Chrome for Windows

Thu, 09 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 08 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Description Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-10T03:55:33.786Z

Reserved: 2026-07-08T17:07:41.990Z

Link: CVE-2026-15120

cve-icon Vulnrichment

Updated: 2026-07-09T10:25:04.948Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T10:45:02Z

Weaknesses