Out of bounds read and write vulnerability in Google Chrome
CVE-2026-15903

8.8HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
20 July 2026

Badges

🔥 Trending now📈 Trended📈 Score: 1,930

What is CVE-2026-15903?

CVE-2026-15903 is a high-severity vulnerability present in Google Chrome, specifically within the V8 JavaScript engine. This flaw arises from an out-of-bounds read and write issue that allows a remote attacker to execute arbitrary code within a restricted environment—referred to as a sandbox—by utilizing a specially crafted HTML page. Google Chrome serves as a widely adopted web browser that provides users with secure browsing capabilities, and any vulnerability within its architecture can potentially expose users to various security threats. The implications of CVE-2026-15903 are particularly concerning as they could lead to unauthorized access to sensitive data, manipulation of web content, or control over the user's device, thereby affecting individual users and organizations that rely on the browser for daily operations.

Potential impact of CVE-2026-15903

  1. Remote Code Execution: The primary consequence of this vulnerability is the ability for remote attackers to execute arbitrary code. This can lead to full system compromise, allowing malicious actors to perform actions such as installing malware, exfiltrating data, or taking control of system resources.

  2. Data Breaches: Exploitation of this vulnerability could result in unauthorized access to sensitive information. Organizations utilizing Google Chrome for business functions may find their proprietary data, customer information, or personal identifiable information (PII) at risk, leading to potential regulatory breaches and reputational damage.

  3. Propagation of Malware and Exploits: By leveraging this vulnerability, attackers can install various types of malware on victims' machines. Once compromised, these systems can be used for launching further attacks, including ransomware distribution, data theft, or as part of a botnet for larger-scale cyber operations.

Affected Version(s)

Chrome 150.0.7871.128

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • 📈

    Vulnerability started trending

  • Vulnerability published

  • Vulnerability Reserved

.