Description
Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-07-20
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a use‑after‑free bug in the CameraCapture module of Chrome on macOS. When a crafted HTML page triggers the deallocation of a camera resource, an attacker can escape Chrome’s renderer sandbox and potentially execute code with elevated privileges, compromising device confidentiality, integrity, and availability.

Affected Systems

Google Chrome on macOS versions prior to 150.0.7871.128 are affected. The issue has been reported in the stable channel and impacts the CameraCapture component.

Risk and Exploitability

The CVSS base score of 9.6 indicates a severe risk, but the EPSS score is less than 1% suggesting a low probability of widespread exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote: a malicious HTML page opened or rendered in Chrome on an affected Mac can trigger the use‑after‑free to escape the sandbox.

Generated by OpenCVE AI on August 4, 2026 at 05:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome on macOS to version 150.0.7871.128 or later, which contains the CameraCapture use‑after‑free fix.
  • If upgrading immediately is not possible, limit camera access by disabling the camera permission or setting Chrome’s site‑permission to deny camera usage for all sites.
  • As a temporary measure, disable the CameraCapture feature via the chrome://flags interface until the patch is applied.

Generated by OpenCVE AI on August 4, 2026 at 05:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4701-1 chromium security update
Debian DSA Debian DSA DSA-6396-1 chromium security update
History

Tue, 04 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Chrome macOS CameraCapture Use‑After‑Free Allows Sandbox Escape

Thu, 30 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Chrome macOS CameraCapture Use‑After‑Free Allows Sandbox Escape

Mon, 27 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome’s CameraCapture Enabling Sandbox Escape

Fri, 24 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome’s CameraCapture Enabling Sandbox Escape

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Mon, 20 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-22T15:48:00.079Z

Reserved: 2026-07-15T18:40:19.018Z

Link: CVE-2026-15899

cve-icon Vulnrichment

Updated: 2026-07-22T13:29:54.222Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-20T23:16:55.637

Modified: 2026-07-27T12:58:16.657

Link: CVE-2026-15899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T06:00:05Z

Weaknesses