Description
Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-14
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Use‑after‑free in the Skia graphics library of Google Chrome occurs when the renderer attempts to use a memory location that has already been deallocated, leading to a sandbox escape when a maliciously crafted HTML page is loaded. The flaw allows a remote attacker who has already compromised the renderer process to elevate privileges within the browser, potentially compromising the confidentiality and integrity of the system. This vulnerability involves a use‑after‑free (CWE‑416) and an improper resource freeing issue (CWE‑825).

Affected Systems

The vulnerability exists in all Google Chrome releases prior to version 150.0.7871.125 on every platform that uses the Skia rendering engine. Users of any affected build are exposed if they load malicious web content that can exploit the renderer.

Risk and Exploitability

With a CVSS score of 8.3 the flaw is high severity, yet the EPSS score of less than 1% indicates exploitation is currently unlikely. It is not listed in the CISA KEV catalog. An attacker would need to first gain control of the renderer—typically by serving a maliciously crafted HTML page or exploiting another renderer issue—and then trigger the use‑after‑free to escape the sandbox. This makes the attack a post‑compromise step rather than a surface‑level vulnerability.

Generated by OpenCVE AI on August 4, 2026 at 07:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Chrome version 150.0.7871.125 or newer from the official channel.
  • Ensure that automatic updates are enabled so that subsequent patches are applied automatically.
  • If an upgrade cannot be performed immediately, restrict the execution of untrusted renderer content by disabling extensions or using separate user profiles, and avoid loading suspicious web pages until the fix is available.

Generated by OpenCVE AI on August 4, 2026 at 07:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4687-1 chromium security update
Debian DSA Debian DSA DSA-6390-1 chromium security update
History

Wed, 29 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Use after free in Skia
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Important


Sat, 25 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Skia Leading to Sandbox Escape in Chrome

Wed, 22 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Skia Leading to Sandbox Escape in Chrome

Fri, 17 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Use After Free in Skia Enables Sandbox Escape via Crafted HTML Page

Thu, 16 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Use After Free in Skia Enables Sandbox Escape via Crafted HTML Page

Wed, 15 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 14 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-14T20:48:32.738Z

Reserved: 2026-07-14T18:31:17.104Z

Link: CVE-2026-15774

cve-icon Vulnrichment

Updated: 2026-07-14T20:48:25.718Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-14T20:09:54Z

Links: CVE-2026-15774 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T07:30:05Z

Weaknesses