Junglewise Threat Intelligence

CVE-2026-15132: Google Chrome uninitialized use in V8

CVE-2026-15132 · Severity: info · Published 2026-07-08

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its V8 JavaScript engine could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is contained within the browser's security sandbox, it represents a significant risk to user data and system integrity.

Technical details

An uninitialized use vulnerability (CWE-457) exists in the V8 JavaScript engine within Google Chrome. A remote attacker can exploit this by enticing a user to visit a malicious website containing a specially crafted HTML page. Successful exploitation allows the attacker to execute arbitrary code within the context of the browser's sandbox. The issue was addressed in Chrome version 150.0.7871.115 for Windows, Mac, and Linux.

Affected products

  • Google Chrome Prior to 150.0.7871.115

Timeline

  • 2026-06-24: disclosed: Reported by Pierre Langlois from Arm
  • 2026-07-08: patched: Fixed in version 150.0.7871.115
  • 2026-07-08: advisory

References

Related threats