Description
Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published: 2026-07-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in Google Chrome’s Linux user interface can be triggered by a malicious web page that forces a user to perform specific gestures. The bug allows an attacker to corrupt the browser’s heap and potentially redirect control flow, which can lead to arbitrary code execution. The weakness is identified as CWE‑416 and CWE‑825.

Affected Systems

Google Chrome installations on Linux that are earlier than version 150.0.7871.125 are affected. Any user running a desktop build of Chrome from the stable channel before that release is at risk.

Risk and Exploitability

The CVSS base score of 7.5 indicates high severity, yet the EPSS score of less than 1 % suggests that known exploits are rare. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user to visit a specially crafted HTML page and perform predetermined UI actions, making it a user‑initiated attack that still demands successful heap corruption for code execution.

Generated by OpenCVE AI on August 4, 2026 at 07:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome on all Linux systems to version 150.0.7871.125 or later, which includes the fixed handling of the use‑after‑free bug
  • Enable or enforce stricter content‑security policies to limit the execution of untrusted JavaScript and reduce the attack surface in the browser
  • Keep Google Chrome updated by regularly checking the official release notes or subscribing to the Chromium issue tracker for new security patches

Generated by OpenCVE AI on August 4, 2026 at 07:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4687-1 chromium security update
Debian DSA Debian DSA DSA-6390-1 chromium security update
History

Wed, 29 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome UI Allows Potential Heap Corruption on Linux chromium-browser: chromium-browser: Use after free in UI
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Important


Tue, 28 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome UI Allows Potential Heap Corruption on Linux

Sun, 26 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free UI Bug in Chrome on Linux Enables Heap Corruption

Wed, 22 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free UI Bug in Chrome on Linux Enables Heap Corruption

Fri, 17 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome UI leading to heap corruption on Linux

Thu, 16 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome UI leading to heap corruption on Linux

Wed, 15 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 14 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Description Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-29T19:26:45.491Z

Reserved: 2026-07-14T18:31:18.056Z

Link: CVE-2026-15777

cve-icon Vulnrichment

Updated: 2026-07-14T20:47:50.703Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-14T20:09:55Z

Links: CVE-2026-15777 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T07:30:05Z

Weaknesses