PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-15900 Google CVE debrief

A critical use after free vulnerability was discovered in the GPU component of Google Chrome on Android versions prior to 150.0.7871.128. This vulnerability, tracked as CVE-2026-15900, could allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page. The vulnerability is rated as Critical by the Chromium security team, with a CVSS score of 9.6. Successful exploitation could lead to sandbox escapes, potentially allowing attackers to execute arbitrary code on the device. Users of Google Chrome on Android are affected, and defenders should verify the affected scope and severity with the official advisory.

Vendor
Google
Product
Chrome
CVSS
CRITICAL 9.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-20
Original CVE updated
2026-07-22
Advisory published
2026-07-20
Advisory updated
2026-07-22

Who should care

This vulnerability affects users of Google Chrome on Android. Successful exploitation could lead to sandbox escapes, potentially allowing attackers to execute arbitrary code on the device. Operators of Google Chrome on Android, platform administrators, and security teams should review the official advisory and take necessary actions to protect their assets.

Technical summary

The vulnerability is a use after free issue in the GPU component of Google Chrome on Android. This occurs when the program attempts to use memory after it has been freed, which can lead to unpredictable behavior. In this case, the vulnerability is rated as Critical by the Chromium security team, with a CVSS score of 9.6. The vulnerability can be exploited via a crafted HTML page, potentially allowing a remote attacker to perform a sandbox escape. Successful exploitation could lead to sandbox escapes, potentially allowing attackers to execute arbitrary code on the device.

Defensive priority

High

Recommended defensive actions

  • Apply the update to Google Chrome on Android to version 150.0.7871.128 or later.
  • Ensure that Google Chrome on Android is set to automatically update.
  • Monitor for any suspicious activity that could be related to this vulnerability.
  • Implement additional security measures such as network traffic monitoring and sandboxing.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record was published on 2026-07-20T23:16:55.763Z and was last modified on 2026-07-22T16:17:10.123Z. The NVD entry is currently Undergoing Analysis. The vulnerability was reported by an external researcher via the Chromium bug bounty program. There is limited information available about the specific details of the vulnerability, and defenders should verify the affected scope and severity with the official advisory. The official CVE record and NVD detail page provide additional context for defenders.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-15900 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-15900

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-15900 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15900

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.