AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-15120

HIGH · CVSS 8.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in the Core component of Google Chrome on Windows allows remote attackers to exploit compromised renderer processes, potentially leading to sandbox escapes via specially crafted HTML pages. This high-severity flaw (CVSS 8.3) poses significant risks to users of affected Chrome versions prior to 150.0.7871.115. Organizations using Chrome on Windows should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-15120
Severity
HIGH
CVSS
8.3
EPSS
0.18%
Windows Chrome

Original NVD Description

Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Related CVEs

Other vulnerabilities affecting the same vendor(s)