Description
Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-08
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in Chrome’s Form handling prior to version 150.0.7871.115 allows a remote attacker to execute arbitrary code by serving a crafted HTML page. The vulnerability is a classic memory corruption bug (CWE‑416), which, once triggered, grants the attacker execution capabilities within the browser’s sandbox. While the sandbox limits system impact, code running in that context can compromise user data, exfiltrate information, or pivot to higher privileges if a sandbox escape or downstream extension is affected.

Affected Systems

All users running Google Chrome stable channel builds older than 150.0.7871.115 are potentially exposed. The exact versions affected are not enumerated in the advisory, but the issue was fixed in the 150.0.7871. is the recommendation for all existing installations.

Risk and Exploitability

The CVE is classified with high severity, yet the EPSS score of less than 1% indicates a low probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be through an attacker‑controlled web page that users visit, since the flaw is triggered by a crafted HTML form. Exploitation would require the user to load the exploit page, so the risk is moderate to high actions limited by the browser sandbox, but the impact could still be significant if sandbox escapes or policy violations occur.

Generated by OpenCVE AI on July 28, 2026 at 09:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Chrome version 150.0.7871.115 or newer to apply the fix for the use‑after‑free flaw.
  • Enable Chrome Enterprise policy to block or restrict form handling for untrusted origins or disable form processing entirely where feasible.
  • Monitor network logs for abnormal HTML form traffic or potential exploitation attempts and investigate.

Generated by OpenCVE AI on July 28, 2026 at 09:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4677-1 chromium security update
Debian DSA Debian DSA DSA-6387-1 chromium security update
History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Forms Enables Remote Code Execution via Malicious Web Pages

Wed, 22 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Forms Enables Remote Code Execution

Thu, 16 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Forms Enables Remote Code Execution

Wed, 15 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Forms Enables Remote Code Execution via Crafted HTML

Mon, 13 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Forms Enables Remote Code Execution via Crafted HTML

Fri, 10 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Forms Enables Remote Code Execution

Thu, 09 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 09 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Forms Enables Remote Code Execution

Thu, 09 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 08 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Description Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-10T03:55:25.522Z

Reserved: 2026-07-08T17:07:43.483Z

Link: CVE-2026-15126

cve-icon Vulnrichment

Updated: 2026-07-09T10:15:47.127Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:15:06Z

Weaknesses