Junglewise Threat Intelligence

CVE-2026-15111: Google Chrome use after free in Views

CVE-2026-15111 · Severity: info · Published 2026-07-08

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its user interface component could allow a remote attacker to compromise a user's computer if they can trick the user into performing specific mouse or keyboard actions on a malicious website. This could lead to the theft of sensitive data or the installation of unauthorized software.

Technical details

A use-after-free (UAF) vulnerability exists in the 'Views' component of Google Chrome. The flaw is triggered when a remote attacker convinces a user to engage in specific UI gestures while visiting a maliciously crafted HTML page. This memory corruption issue (CWE-416) can lead to heap corruption, potentially allowing for arbitrary code execution within the browser's sandbox. The vulnerability was addressed in Chrome version 150.0.7871.115 for Windows and Mac, and 150.0.7871.114 for Linux.

Affected products

  • Google Chrome prior to 150.0.7871.115

Timeline

  • 2026-05-28: disclosed: Reported to Google internally
  • 2026-07-08: patched: Stable channel update released
  • 2026-07-08: advisory

References

Related threats