Description
Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High)
Published: 2026-07-14
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a heap buffer overflow in the libyuv component of Google Chrome that exists on Windows systems running versions earlier than 150.0.7871.125. A malicious video file crafted by an attacker can cause the overflow, allowing the attacker to execute arbitrary code within the browser's sandbox. The flaw is classified as CWE-122 and CWE-787, indicating an uncontrolled allocation on the heap and an out‑of‑bounds write.

Affected Systems

Windows users who have Google Chrome installed before version 150.0.7871.125 are affected. No other operating systems or Chrome versions are mentioned in the CVE data, so the scope is limited to that specific Windows build and older Chrome releases.

Risk and Exploitability

The CVSS score of 8.8 signals a high‑severity remote code execution risk. The EPSS score of <1% indicates currently low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, meaning there are no confirmed widespread attacks. An attacker would need to deliver a crafted video file to a user; if the file is opened or processed by Chrome, the attacker can run code inside the browser sandbox with the privileges of the current user. The exploitation remains confined to the browser context and does not automatically grant system‑level privileges.

Generated by OpenCVE AI on August 3, 2026 at 03:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.125 or later.
  • Apply all relevant security updates to the underlying Windows operating system.
  • Employ reputable anti‑malware or endpoint protection solutions that monitor for and block suspicious media activity.

Generated by OpenCVE AI on August 3, 2026 at 03:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4687-1 chromium security update
Debian DSA Debian DSA DSA-6390-1 chromium security update
History

Wed, 29 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: libyuv: chromium-browser: Heap buffer overflow in libyuv
Weaknesses CWE-787
References
Metrics threat_severity

None

threat_severity

Important


Sat, 25 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in libyuv Allows Remote Code Execution via Crafted Video

Fri, 17 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Heap Buffer Overflow in libyuv Allows Remote Code Execution via Crafted Video

Wed, 15 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 14 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High)
Weaknesses CWE-122
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-15T04:01:05.101Z

Reserved: 2026-07-14T18:31:15.057Z

Link: CVE-2026-15767

cve-icon Vulnrichment

Updated: 2026-07-14T20:43:35.435Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-14T20:09:51Z

Links: CVE-2026-15767 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:15:05Z

Weaknesses