Junglewise Threat Intelligence

CVE-2026-15120: Google Chrome use after free in Core

CVE-2026-15120 · Severity: info · Published 2026-07-08

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its core components could allow a remote attacker to bypass security protections (the 'sandbox') that normally isolate the browser from the rest of the computer. If exploited, this could allow an attacker who has already gained a foothold in the browser to gain broader access to the underlying Windows operating system.

Technical details

A use-after-free vulnerability exists in the Core component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during the processing of a crafted HTML page. To exploit this, an attacker must first compromise the renderer process (typically via a separate vulnerability). Once the renderer is compromised, this flaw allows the attacker to escape the Chrome sandbox and execute code with higher privileges on the host Windows system. The issue is resolved in version 150.0.7871.115.

Affected products

  • Google Chrome prior to 150.0.7871.115

Timeline

  • 2026-06-13: disclosed: Reported to Google
  • 2026-07-08: patched: Stable channel update released
  • 2026-07-08: advisory

References

Related threats