Skip to content
GoogleCVE-2026-15122

Google Chrome: improper input validation

High8.3CVE-2026-15122 · Published Jul 8, 2026 · updated Jul 10, 2026

Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Google advisory

Affected versions

PackageAffectedFixed in
Chrome
Product
>= 150.0.7871.115, < 150.0.7871.115150.0.7871.115
Details and references

More Google advisories

All Google
Advisory
Google Chrome: use after free
High8.8Jul 8
Google Chrome: remote attacker could bypass site isolation
Medium4.3Jul 8
Google Chrome: remote attacker could bypass site isolation
Medium4.3Jul 8
Google Chrome: remote code execution
High8.8Jul 8
Google Chrome: use after free
High8.8Jul 8
Google Chrome: race condition
High8.3Jul 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.