Description
Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw in the WebRTC implementation of Google Chrome. A maliciously crafted HTML page can cause the browser to use memory that has already been freed, allowing an attacker to execute arbitrary code within Chrome’s sandboxed process. This flaw falls under CWE‑416. The primary impact is remote code execution, which could compromise the integrity of the victim’s device and enable further malicious activity.

Affected Systems

All installations of Google Chrome with versions earlier than 150.0.7871.115 are affected. This includes stable channel builds released in 2026 across Windows, macOS, Linux, and Android. Users or organizations that have not upgraded beyond this version remain vulnerable to exploitation via a crafted HTML page.

Risk and Exploitability

Chrome’s team assigned a CVSS score of 8.8, indicating high severity. The EPSS score is below 1%, suggesting a low probability of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog, implying no publicly known exploits at this time. Based on the description, it is inferred that the attack vector requires delivery of a crafted HTML page, typically accessed via HTTP or HTTPS, which triggers the use‑after‑free within the WebRTC code path.

Generated by OpenCVE AI on July 23, 2026 at 10:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.115 or later
  • If an immediate update is not possible, disable WebRTC functionality via chrome://flags or a group policy setting to block related APIs
  • Monitor user systems for suspicious browser activity and apply subsequent security updates promptly

Generated by OpenCVE AI on July 23, 2026 at 10:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4677-1 chromium security update
Debian DSA Debian DSA DSA-6387-1 chromium security update
History

Thu, 23 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Use‑after‑Free in WebRTC Allows Remote Code Execution via Crafted HTML Page

Tue, 21 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome WebRTC allows remote code execution via crafted HTML page

Thu, 16 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome WebRTC allows remote code execution via crafted HTML page

Wed, 15 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome WebRTC Enables Remote Code Execution

Tue, 14 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome WebRTC Enables Remote Code Execution

Sun, 12 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome WebRTC Allows Remote Code Execution

Sat, 11 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome WebRTC Allows Remote Code Execution

Fri, 10 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via WebRTC Use After Free in Google Chrome

Thu, 09 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via WebRTC Use After Free in Google Chrome

Thu, 09 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 08 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Description Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-10T03:55:36.126Z

Reserved: 2026-07-08T17:07:42.270Z

Link: CVE-2026-15121

cve-icon Vulnrichment

Updated: 2026-07-09T13:41:04.975Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-23T10:45:02Z

Weaknesses