Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-15773

CVE-2026-15773: Google Chrome Use After Free Vulnerability

CVE-2026-15773 is a use after free vulnerability in Google Chrome on Windows that enables remote attackers to escape the sandbox via crafted HTML. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-15773 Overview

CVE-2026-15773 is a use-after-free vulnerability in the Core component of Google Chrome on Windows. Versions prior to 150.0.7871.125 are affected. A remote attacker can trigger the flaw by convincing a user to load a crafted HTML page. Successful exploitation may lead to a sandbox escape, allowing attacker-controlled code to break out of the renderer process boundary. The issue is tracked under [CWE-416] and carries a Chromium security severity rating of High.

Critical Impact

Remote attackers can achieve sandbox escape from a single crafted web page, breaking Chrome's primary security boundary on Windows endpoints.

Affected Products

  • Google Chrome on Windows prior to 150.0.7871.125
  • Microsoft Windows hosts running affected Chrome builds
  • Chromium-derived browsers sharing the vulnerable Core component

Discovery Timeline

  • 2026-07-14 - CVE-2026-15773 published to NVD
  • 2026-07-15 - Last updated in NVD database

Technical Details for CVE-2026-15773

Vulnerability Analysis

The defect is a use-after-free condition in Chrome's Core subsystem. A use-after-free occurs when a program continues to reference heap memory that has already been released. An attacker who controls the freed allocation can shape subsequent heap reuse to place attacker-controlled data at the dangling pointer location.

In the browser context, exploitation typically begins in the renderer process through a crafted HTML page. Because the flaw resides in Core code that interacts with higher-privileged browser components, successful memory corruption can be chained to escape the renderer sandbox. Sandbox escape on Windows grants the attacker execution in a broker process with substantially wider access to the host operating system.

The CVSS vector indicates network-based attack, low complexity, no privileges, and required user interaction limited to loading a page. The scope change reflects that impact extends beyond the vulnerable component into other security domains, which aligns with sandbox escape behavior.

Root Cause

The root cause is object lifetime mismanagement within Chrome Core. A reference to a heap object persists after the object has been freed, and later code paths dereference that stale pointer. Google has not published low-level implementation details. See the Chromium Issue Tracker entry for restricted technical context.

Attack Vector

Delivery requires only that a targeted user visits a malicious page or a compromised legitimate site serving the crafted content. Typical distribution channels include phishing links, malicious advertisements, and watering-hole attacks. No authentication is required, and the exploit runs without elevated privileges on the victim host.

No public proof-of-concept, exploit code, or CISA KEV entry has been observed at the time of publication. The EPSS probability reported for this CVE remains low, but the sandbox-escape impact warrants prompt patching regardless.

Detection Methods for CVE-2026-15773

Indicators of Compromise

  • Chrome renderer or browser process crashes correlated with visits to unfamiliar domains, particularly access violations in chrome.dll
  • Child processes spawned by chrome.exe that are inconsistent with normal browser behavior, such as cmd.exe, powershell.exe, or rundll32.exe
  • Unexpected outbound connections initiated by Chrome broker processes to attacker infrastructure
  • Creation of persistence artifacts (Run keys, scheduled tasks) shortly after Chrome activity

Detection Strategies

  • Hunt for anomalous process ancestry where Chrome is the parent of shell interpreters or scripting hosts
  • Alert on Chrome process crashes with exception codes indicative of heap corruption, such as 0xC0000005 in the renderer
  • Correlate WER (Windows Error Reporting) telemetry with browsing history to identify pages that repeatedly trigger crashes

Monitoring Recommendations

  • Track installed Chrome versions across the fleet and flag hosts running builds below 150.0.7871.125
  • Monitor endpoint telemetry for renderer-to-broker anomalies and unexpected token elevation within Chrome process trees
  • Enable full command-line and module-load logging for chrome.exe to enrich post-incident triage

How to Mitigate CVE-2026-15773

Immediate Actions Required

  • Update Google Chrome on all Windows endpoints to version 150.0.7871.125 or later
  • Restart the browser after installation so patched binaries are loaded into memory
  • Verify managed browser policies force automatic updates and prevent version pinning to vulnerable builds
  • Prioritize patching for high-risk users such as executives, developers, and administrators

Patch Information

Google released the fix in the Chrome Stable channel. Details are published in the Google Chrome Stable Update announcement. Chromium-based browsers should be updated once vendors incorporate the upstream fix.

Workarounds

  • Restrict browsing to trusted sites using enterprise proxy or DNS filtering until patches are deployed
  • Deploy Chrome enterprise policies that block ad networks and untrusted script origins
  • Consider temporary use of site isolation and strict SameSite cookie policies to reduce exposure surface
  • Educate users to avoid clicking unsolicited links pending update rollout
bash
# Verify installed Chrome version on Windows endpoints
reg query "HKLM\SOFTWARE\Google\Update\Clients\{8A69D345-D564-463C-AFF1-A69D9E530F96}" /v pv

# Force update via Chrome enterprise policy (GPO registry)
reg add "HKLM\SOFTWARE\Policies\Google\Update" /v UpdateDefault /t REG_DWORD /d 1 /f
reg add "HKLM\SOFTWARE\Policies\Google\Update" /v AutoUpdateCheckPeriodMinutes /t REG_DWORD /d 60 /f

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.