Description
Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
Published: 2026-07-20
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw in the Aura component of Google Chrome that permits heap corruption. An attacker can supply a malicious file that, when processed by Chrome, corrupts the heap. The weakness is formally identified as CWE‑416: Use After Free.

Affected Systems

Affected is the Google Chrome browser. Versions prior to 150.0.7871.128 are vulnerable, including all prior stable channel releases. No other Chrome variants or products are explicitly listed as affected.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity impact if exploited. The EPSS score of less than 1% shows a very low probability of exploitation in the wild, and the vulnerability is not included in the CISA KEV catalog. The likely attack vector is local: a user who can place a malicious file on the machine and have Chrome parse it – an attacker with local or physical access could aim to trigger the use‑after‑free. No network‑based or remote execution path is described.

Generated by OpenCVE AI on August 1, 2026 at 07:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.128 or later
  • Configure the operating system to block execution of untrusted files that might be opened by Chrome
  • Ensure Chrome auto‑update is enabled so future security fixes are applied automatically

Generated by OpenCVE AI on August 1, 2026 at 07:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4701-1 chromium security update
Debian DSA Debian DSA DSA-6396-1 chromium security update
History

Sat, 01 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Aura Component Enabling Local Heap Corruption

Fri, 24 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Aura Component Enabling Local Heap Corruption

Wed, 22 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 21 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Description Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-21T13:03:00.211Z

Reserved: 2026-07-15T18:40:20.911Z

Link: CVE-2026-15905

cve-icon Vulnrichment

Updated: 2026-07-21T13:02:15.060Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T07:15:03Z

Weaknesses