Junglewise Threat Intelligence

CVE-2026-15775: Google Chrome Same Origin Policy bypass in V8

CVE-2026-15775 · Severity: info · CVSS 8.8 · Published 2026-07-14

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its V8 JavaScript engine could allow a malicious website to bypass the Same Origin Policy, which is a fundamental security boundary. If exploited, this could allow an attacker to access sensitive data from other websites you have open, such as login sessions or personal information.

Technical details

A vulnerability classified as 'Insufficient policy enforcement' exists in the V8 JavaScript engine of Google Chrome. The flaw allows a remote attacker to bypass the Same Origin Policy (SOP) by enticing a user to visit a specially crafted HTML page. Successful exploitation could lead to unauthorized access to sensitive information or cross-site data theft. The issue is resolved in Google Chrome version 150.0.7871.125 for Windows and Mac, and 150.0.7871.124 for Linux.

Affected products

  • Google Chrome Prior to 150.0.7871.125

Timeline

  • 2026-07-05: disclosed: Reported to Chromium by researcher
  • 2026-07-14: patched: Stable channel update released
  • 2026-07-14: advisory: NVD publication date

References

Related threats