Multiple vulnerabilities in Google Chrome (July 17, 2026)
Multiple vulnerabilities have been discovered in Google Chrome. They allow an attacker to cause an unspecified security issue by the vendor.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to cause an unspecified security issue.
- Who is affected
- Users of Google Chrome are affected.
- Urgency
- Remediation is necessary as the severity is unknown and exploitation could lead to security issues.
- Action
- Update to the latest version of Google Chrome.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Chrome
Get an email when a new Chrome advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0897/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-159030.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
- Low exploitation riskCVE-2026-159050.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
- Low exploitation riskCVE-2026-159010.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
- Low exploitation riskCVE-2026-159000.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-159040.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-158990.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-159020.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-15903 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15905 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15901 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15900 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15904 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15899 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15902 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Google Chrome: Multiple vulnerabilities allow unspecified attackcert-bund
- unknownDSA-6396-1 chromium - security updatedebian
- highCVE-2026-15905: Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to po…nvd
- highCVE-2026-15904: Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote att…nvd
- highCVE-2026-15903: Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote a…nvd
- highCVE-2026-15902: Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to e…nvd
- criticalCVE-2026-15901: Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker t…nvd
- criticalCVE-2026-15900: Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote att…nvd
- criticalCVE-2026-15899: Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remo…nvd
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Microsoft Edge (July 20, 2026)cert-fr-avis
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert
Recent advisories for Google Chrome
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Google Chrome: Multiple vulnerabilitiescert-bund · 2026-07-30
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert · 2026-07-30
- mediumCVE-2026-18019: Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a re…nvd · 2026-07-30
- mediumCVE-2026-18018: Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 all…nvd · 2026-07-30
- highCVE-2026-18017: Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to ex…nvd · 2026-07-30
- mediumCVE-2026-18016: Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.…nvd · 2026-07-30
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans PHP (31 juillet 2026)2026-07-31
- unknownVulnérabilité dans Microsoft Azure (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Red Hat (31 juillet 2026)2026-07-31