SEPTEMBER 11, 2026
Live Feed
Back to database
Case File

CVE-2026-15767

HIGH · CVSS 8.8 EPSS 0.35%

Source: NVD + CISA KEV + EPSS · Published 2026-07-14 · Last synced 2026-08-13

CyberRota Analysis

AI-Generated

A heap buffer overflow vulnerability in the libyuv component of Google Chrome on Windows allows remote attackers to execute arbitrary code within a sandbox by leveraging a specially crafted video file. This poses a significant risk, particularly for organizations that utilize Chrome for web browsing, as it could lead to unauthorized access or control over affected systems. Users and administrators should prioritize patching to versions 150.0.7871.125 or later to mitigate potential exploitation.

CVE
CVE-2026-15767
Severity
HIGH
CVSS
8.8
EPSS
0.35%
Windows Chrome

Original NVD Description

Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: High)

Related CVEs

Other vulnerabilities affecting the same vendor(s)