CVE-2026-15132
published 2026-07-08CVE-2026-15132: Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page…
PriorityP352high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.27%
19.0th percentile
Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 150.0.7871.115 | 150.0.7871.115 | |
| chrome | >= 150.0.7871.115 < 150.0.7871.115 | 150.0.7871.115 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 150.0.7871.47 V8 uninitialized pointer
vuldb·2026-07-09
CVE-2026-15132 [CRITICAL] Google Chrome up to 150.0.7871.47 V8 uninitialized pointer
A vulnerability categorized as critical has been discovered in Google Chrome. This issue affects some unknown processing of the component V8. Such manipulation leads to uninitialized pointer.
This vulnerability is traded as CVE-2026-15132. The attack may be launched remotely. There is no exploit available.
GHSA
Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
ghsa_unreviewed·2026-07-09
CVE-2026-15132 [HIGH] CWE-457 Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-15132
vendor_chrome·2026-07-16
CVE-2026-15132 Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-15132
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2026-15132
Chrome
Stable Channel Update for Desktop: CVE-2026-15112
vendor_chrome·2026-07-08
CVE-2026-15112 [CRITICAL] Stable Channel Update for Desktop: CVE-2026-15112
Stable Channel Update for Desktop
CVE-2026-15112: Use after free in Ozone. Reported by Google on 2026-05-29 [N/A][ 524045160 ] Critical CVE-2026-15129: Use after free in Views
Reported by Google on 2026-06-15 [$500][ 527385397 ] High CVE-2026-15132: Uninitialized Use in V8
Severity: critical
Red Hat
chromium-browser: chromium-browser: Uninitialized Use in V8
vendor_redhat·2026-07-08·CVSS 8.8
CVE-2026-15132 [HIGH] CWE-824 chromium-browser: chromium-browser: Uninitialized Use in V8
chromium-browser: chromium-browser: Uninitialized Use in V8
Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
An uninitialized use flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=527385397
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
No detection rules found.
No public exploits indexed.
2026-07-08
Published