Description
Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-07-20
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw exists in the Network component of Google Chrome. A maliciously crafted HTML page can trigger a heap corruption, potentially allowing an attacker to execute arbitrary code. This flaw is classified as CWE‑416 and is rated as critical by Chromium security.

Affected Systems

Google Chrome versions prior to 150.0.7871.128 on the stable desktop channel are affected. Users running these older releases are susceptible to the use‑after‑free during page rendering.

Risk and Exploitability

The most likely attack vector is a crafted HTML page served by an attacker that the victim opens. The CVSS score of 9.6 reflects a high severity level, but the EPSS score of < 1 % suggests that exploitation remains uncommon at present. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation at the time of this analysis.

Generated by OpenCVE AI on August 4, 2026 at 05:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.128 or later.
  • Ensure Chrome’s automatic update feature is enabled so future security patches are applied without manual intervention.
  • If an immediate upgrade cannot be performed, deploy Chrome Enterprise policies that enforce Safe Browsing and restrict access to untrusted sites until the vulnerable component is fixed.

Generated by OpenCVE AI on August 4, 2026 at 05:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4701-1 chromium security update
Debian DSA Debian DSA DSA-6396-1 chromium security update
History

Tue, 04 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Use‑After‑Free in Chrome Network Component

Thu, 30 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Network Component Enables Heap Corruption

Wed, 29 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Network Component Enables Heap Corruption

Wed, 22 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Mon, 20 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-22T15:47:39.718Z

Reserved: 2026-07-15T18:40:19.619Z

Link: CVE-2026-15901

cve-icon Vulnrichment

Updated: 2026-07-22T15:10:13.044Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-20T23:16:55.877

Modified: 2026-07-24T15:08:22.467

Link: CVE-2026-15901

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T06:00:05Z

Weaknesses