CVE-2026-15903
published 2026-07-20CVE-2026-15903: Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted…
PriorityP354high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.31%
23.8th percentile
Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 150.0.7871.128 | 150.0.7871.128 | |
| chrome | >= 150.0.7871.128 < 150.0.7871.128 | 150.0.7871.128 | |
| chrome_desktop | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
ghsa_unreviewed·2026-07-21
CVE-2026-15903 Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
VulDB
Google Chrome up to 150.0.7871.125 V8 out-of-bounds write (WID-SEC-2026-2398)
vuldb·2026-07-18
CVE-2026-15903 [CRITICAL] Google Chrome up to 150.0.7871.125 V8 out-of-bounds write (WID-SEC-2026-2398)
A vulnerability was found in Google Chrome and classified as critical. The impacted element is an unknown function of the component V8. Such manipulation leads to out-of-bounds write.
This vulnerability is referenced as CVE-2026-15903. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
Chrome
Stable Channel Update for Desktop: CVE-2026-15902
vendor_chrome·2026-07-16
CVE-2026-15902 [HIGH] Stable Channel Update for Desktop: CVE-2026-15902
Stable Channel Update for Desktop
CVE-2026-15902: Use after free in Cast. Reported by Google on 2026-06-10 [TBD][ 531503216 ] High CVE-2026-15903: Out of bounds read and write in V8
Reported by OpenAI Codex Security (amyb) on 2026-07-06 [N/A][ 532925350 ] High CVE-2026-15904: Use after free in Ozone
Severity: high
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-20
Published