Junglewise Threat Intelligence

CVE-2026-15900: Google Chrome use after free in GPU

CVE-2026-15900 · Severity: info · Published 2026-07-20

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome for Android that could allow a malicious website to bypass the browser's security sandbox. By tricking a user into visiting a specially crafted webpage, an attacker could potentially gain unauthorized access to the underlying operating system or user data. This issue affects the GPU component, which handles graphics rendering, and could lead to a complete compromise of the device's security boundaries.

Technical details

A use-after-free (UAF) vulnerability exists in the GPU component of Google Chrome for Android (CWE-416). The flaw is triggered when the browser incorrectly manages memory during graphics processing, allowing a remote attacker to execute arbitrary code or escape the process sandbox by enticing a user to visit a malicious HTML page. This is classified as a Critical severity issue by Chromium. The vulnerability is addressed in version 150.0.7871.128 and later. The attack vector is remote and requires no special privileges other than the ability to serve web content to the victim.

Affected products

  • Google Chrome prior to 150.0.7871.128

Timeline

  • 2026-06-14: disclosed: Reported to Google internally
  • 2026-07-16: patched: Stable channel update released
  • 2026-07-20: advisory: NVD publication date

References

Related threats