CVE-2026-15778
published 2026-07-14CVE-2026-15778: Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer…
PriorityP433medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.25%
16.8th percentile
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 150.0.7871.125 | 150.0.7871.125 | |
| chrome | >= 150.0.7871.125 < 150.0.7871.125 | 150.0.7871.125 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-15778
vendor_chrome·2026-07-16
CVE-2026-15778 Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-15778
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2026-15778
Chrome
Stable Channel Update for Desktop: CVE-2026-15776
vendor_chrome·2026-07-14·CVSS 8.8
CVE-2026-15776 [HIGH] Stable Channel Update for Desktop: CVE-2026-15776
Stable Channel Update for Desktop
CVE-2026-15776: Type Confusion in V8. Reported by Salvatore Gulizia (nickname: Serotav) on 2026-07-08 [N/A][ 532929679 ] High CVE-2026-15777: Use after free in UI
Reported by Google on 2026-07-09 [N/A][ 513795122 ] Medium CVE-2026-15778: Insufficient validation of untrusted input in Navigation
Severity: high
Red Hat
chromium-browser: chromium-browser: Insufficient validation of untrusted input in Navigation
vendor_redhat·2026-07-14·CVSS 6.5
CVE-2026-15778 [MEDIUM] CWE-1289 chromium-browser: chromium-browser: Insufficient validation of untrusted input in Navigation
chromium-browser: chromium-browser: Insufficient validation of untrusted input in Navigation
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
An insufficient validation of untrusted input flaw was found in the Navigation component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=513795122
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
GHSA
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions v
ghsa_unreviewed·2026-07-14
CVE-2026-15778 [MEDIUM] CWE-20 Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions v
Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
No detection rules found.
No public exploits indexed.
2026-07-14
Published