Description
Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-14
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in Google Chrome’s core component on Windows allows a maliciously crafted HTML page to trigger a memory corruption bug. The defect can lead to a sandbox escape, giving the attacker execution capabilities beyond the browser process. If the attacker succeeds, arbitrary code could run with the privileges of the user, potentially escalating to full system compromise.

Affected Systems

Google Chrome for Windows versions prior to 150.0.7871.125 are vulnerable. Users of those releases on Windows machines are susceptible and should update to the patched version or later.

Risk and Exploitability

The CVSS score of 9.6 indicates high severity, yet the EPSS score of less than 1% suggests only a very low current likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread attacks. The likely attack path is that a remote adversary serves a specially crafted HTML page to a Windows user running an affected Chrome version, potentially enabling sandbox escape and code execution.

Generated by OpenCVE AI on August 4, 2026 at 18:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Chrome update to release 150.0.7871.125 or newer on all Windows machines.
  • Configure Chrome’s auto‑update policy to ensure the browser automatically receives the latest security patches.
  • Enforce strict web filtering or content‑disallow policies in enterprise environments to mitigate execution of unknown or malicious HTML content.

Generated by OpenCVE AI on August 4, 2026 at 18:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4687-1 chromium security update
Debian DSA Debian DSA DSA-6390-1 chromium security update
History

Wed, 29 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Use after free in Core
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Important


Sun, 26 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Core Leading to Sandbox Escape

Wed, 22 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Core Leading to Sandbox Escape

Mon, 20 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote code execution via use‑after‑free in Chrome sandbox escape

Thu, 16 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Remote code execution via use‑after‑free in Chrome sandbox escape

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 14 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-14T20:49:02.843Z

Reserved: 2026-07-14T18:31:16.814Z

Link: CVE-2026-15773

cve-icon Vulnrichment

Updated: 2026-07-14T20:49:00.093Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-14T20:09:54Z

Links: CVE-2026-15773 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T18:45:12Z

Weaknesses