Junglewise Threat Intelligence

CVE-2026-15118: Google Chrome use after free in Input

CVE-2026-15118 · Severity: info · CVSS 8.8 · Published 2026-07-08

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser for accessing the internet and running web applications. A security vulnerability in the browser's input handling component could allow a malicious website to execute unauthorized code on a user's computer. While the attack is limited by the browser's security sandbox, it could lead to data theft or be used as part of a larger attack to compromise the entire system.

Technical details

A use-after-free (UAF) vulnerability exists in the Input component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of user input or events, allowing a remote attacker to exploit the memory corruption via a crafted HTML page. Successful exploitation allows for arbitrary code execution (ACE) within the context of the Chromium sandbox. This vulnerability affects Google Chrome versions prior to 150.0.7871.115. Users are advised to update to the latest stable channel release to mitigate this risk.

Affected products

  • Google Chrome prior to 150.0.7871.115

Timeline

  • 2026-06-12: disclosed: Reported to Google by internal researchers
  • 2026-07-08: patched: Fixed in version 150.0.7871.115 for Windows/Mac and 150.0.7871.114 for Linux
  • 2026-07-08: advisory

References

Related threats