Threat Advisory

Google Chrome Vulnerabilities Impact CameraCapture Component

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple vulnerabilities have been identified in Google Chrome for desktop platforms. This release addresses seven distinct flaws, primarily consisting of use-after-free issues alongside an out-of-bounds memory vulnerability in the V8 JavaScript engine. These weaknesses pose significant business risk as they could allow attackers to bypass sandboxes and execute arbitrary code on affected systems through malicious web content. Successful exploitation could lead to unauthorized system access, data theft, or full compromise of the endpoint, making immediate attention necessary to maintain the integrity of corporate browsing environments.

CVE-2026-15901 (CVSS 9.1 — Critical): It is a use-after-free vulnerability in the Network component allows an attacker to execute arbitrary code by filling freed memory with malicious data.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple vulnerabilities have been identified in Google Chrome for desktop platforms. This release addresses seven distinct flaws, primarily consisting of use-after-free issues alongside an out-of-bounds memory vulnerability in the V8 JavaScript engine. These weaknesses pose significant business risk as they could allow attackers to bypass sandboxes and execute arbitrary code on affected systems through malicious web content. Successful exploitation could lead to unauthorized system access, data theft, or full compromise of the endpoint, making immediate attention necessary to maintain the integrity of corporate browsing environments.

CVE-2026-15901 (CVSS 9.1 — Critical): It is a use-after-free vulnerability in the Network component allows an attacker to execute arbitrary code by filling freed memory with malicious data.[emaillocker id="1283"]

CVE-2026-15903 (CVSS 8.8 — High): It is an out-of-bounds read and write vulnerability in the V8 engine allows an attacker to read or write to arbitrary memory locations, potentially leading to code execution.

CVE-2026-15899 (CVSS 9.2 — Critical): It is a use-after-free vulnerability in CameraCapture allows an attacker to execute arbitrary code by controlling memory content after it is freed via untrusted web content.

CVE-2026-15900 (CVSS 9.4 — Critical): It is a use-after-free vulnerability in the GPU component allows an attacker to steer execution by manipulating memory pointers after they have been released.

CVE-2026-15902 (CVSS 8.7 — High): It is a use-after-free vulnerability in the Cast component allows an attacker to corrupt memory and potentially execute code through crafted web content.

CVE-2026-15904 (CVSS 8.6 — High): It is a use-after-free vulnerability in the Ozone component allows an attacker to exploit memory management errors to execute arbitrary code.

CVE-2026-15905 (CVSS 8.4 — High): It is a use-after-free vulnerability in the Aura component allows an attacker to control program execution by filling freed memory with specific data.

RECOMMENDATION:

We recommend you to update Google Chrome for Linux to version 150.0.7871.128 and for Windows, macOS to version 150.0.7871.128/.129 or later.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu