Junglewise Threat Intelligence

CVE-2026-15114: Google Chrome out of bounds read and write in Codecs

CVE-2026-15114 · Severity: info · Published 2026-07-08

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its video processing component (Codecs) allows a remote attacker to potentially crash the browser or execute unauthorized code if a user opens a specially crafted video file. This could lead to the compromise of the user's computer or the theft of sensitive information handled within the browser.

Technical details

An out-of-bounds (OOB) read and write vulnerability exists in the Codecs component of Google Chrome. The flaw is triggered when the browser processes a specially crafted video file, leading to heap corruption. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website or open a malicious video file. Successful exploitation could allow for arbitrary code execution within the context of the browser's sandbox or a denial-of-service (browser crash). The issue is resolved in Google Chrome version 150.0.7871.115 for Windows and Mac, and 150.0.7871.114 for Linux.

Affected products

  • Google Chrome prior to 150.0.7871.115

Timeline

  • 2026-06-06: disclosed: Reported by Google internally
  • 2026-07-08: patched: Fixed in stable channel update 150.0.7871.114/.115
  • 2026-07-08: advisory

References

Related threats