Description
Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is caused by an inappropriate handling of form data in Google Chrome before version 150.0.7871.115. A maliciously crafted HTML page can trigger the browser to run arbitrary code inside its sandboxed environment. This is a CWE-863 flaw that permits code execution with the privileges of the user’s Chrome process while remaining confined to the sandbox. The impact includes potential compromise of confidentiality, integrity, and availability of data within the browser.

Affected Systems

Google Chrome desktop editions prior to 150.0.7871.115 are affected. The vulnerability exists on all desktop operating systems where Chrome is installed, until the patch is applied.

Risk and Exploitability

Experts infer that the attack requires a user to load a malicious HTML page, making the vector remote and user‑initiated. The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% points to a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread active exploits are known. Nonetheless, because the flaw allows code execution within the browser process, administrators should consider immediate remediation to prevent future exploitation.

Generated by OpenCVE AI on July 28, 2026 at 09:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.115 or newer released by Google
  • Enforce Chrome update policies (e.g., Windows Group Policy or macOS MDM) to ensure endpoints receive the patch promptly
  • As a temporary measure, restrict untrusted form submissions through web filtering or Chrome policy until the vulnerability is fully patched

Generated by OpenCVE AI on July 28, 2026 at 09:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4677-1 chromium security update
Debian DSA Debian DSA DSA-6387-1 chromium security update
History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Chrome Forms Handling Vulnerability Enabling Remote Code Execution

Wed, 22 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Chrome Forms Handling Vulnerability Enabling Remote Code Execution

Wed, 15 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Chrome Forms Vulnerability Allows Remote Code Execution

Mon, 13 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Chrome Forms Vulnerability Allows Remote Code Execution

Mon, 13 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Form Handling in Google Chrome

Sun, 12 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Form Handling in Google Chrome

Sat, 11 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Chrome Form Handling Bug Enables Remote Code Execution Inside Sandbox

Fri, 10 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Chrome Form Handling Bug Enables Remote Code Execution Inside Sandbox

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Inadequate Form Handling Leads to Remote Code Execution in Chrome
Weaknesses CWE-94

Thu, 09 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-863
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Inadequate Form Handling Leads to Remote Code Execution in Chrome
Weaknesses CWE-94

Thu, 09 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 08 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-10T03:55:26.297Z

Reserved: 2026-07-08T17:07:43.236Z

Link: CVE-2026-15125

cve-icon Vulnrichment

Updated: 2026-07-09T10:16:27.465Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:15:06Z

Weaknesses