Junglewise Threat Intelligence

CVE-2026-15899: Google Chrome use after free in CameraCapture

CVE-2026-15899 · Severity: info · Published 2026-07-20

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability was identified in Google Chrome for macOS that could allow a malicious website to break out of the browser's security sandbox. Chrome is a widely used web browser, and the sandbox is a primary defense mechanism that prevents malicious code from accessing the rest of the computer. If exploited, an attacker could gain unauthorized access to the underlying operating system and user data.

Technical details

A use-after-free (UAF) vulnerability exists in the CameraCapture component of Google Chrome for macOS. The flaw is triggered when the browser incorrectly manages memory during camera capture operations, allowing a remote attacker to exploit the memory corruption via a specially crafted HTML page. This vulnerability is classified as Critical because it can lead to a sandbox escape, allowing code execution outside of the restricted browser process. The issue was addressed in Chrome version 150.0.7871.128.

Affected products

  • Google Chrome prior to 150.0.7871.128

Timeline

  • 2026-05-27: disclosed: Reported by Google internal researchers
  • 2026-07-16: patched: Fixed in stable channel update 150.0.7871.128/.129
  • 2026-07-20: advisory: NVD publication date

References

Related threats