[NEW] [high] Google Chrome: Multiple vulnerabilities
A remote, anonymous attacker can exploit multiple vulnerabilities in Google Chrome to execute arbitrary program code, bypass security mechanisms, or achieve other unspecified impacts.
CSIRTS triage
- What
- A remote, anonymous attacker can exploit multiple vulnerabilities in Google Chrome to execute arbitrary program code, bypass security mechanisms, or achieve other unspecified impacts.
- Who is affected
- Users of Google Chrome.
- Urgency
- Remediation is high urgency due to the potential for arbitrary code execution.
- Action
- Update Google Chrome to the latest version immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Chrome
Get an email when a new Chrome advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2347
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-157640.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all scored CVEs.
- Low exploitation riskCVE-2026-157650.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 39% of all scored CVEs.
- Low exploitation riskCVE-2026-157660.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-157670.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all scored CVEs.
- Low exploitation riskCVE-2026-157680.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 13% of all scored CVEs.
- Low exploitation riskCVE-2026-157690.23% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 14% of all scored CVEs.
- Low exploitation riskCVE-2026-157700.30% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 23% of all scored CVEs.
- Low exploitation riskCVE-2026-157710.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all scored CVEs.
- Low exploitation riskCVE-2026-157720.22% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 12% of all scored CVEs.
- Low exploitation riskCVE-2026-157730.29% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 22% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-15764 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15765 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15766 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15767 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15768 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15769 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15770 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15771 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15772 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15773 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15774 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15775 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15776 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15777 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15778 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownMultiple Vulnerabilities in Microsoft Edge (July 29, 2026)cert-fr-avis
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Microsoft Edge (July 20, 2026)cert-fr-avis
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert
- unknownDSA-6390-1 chromium - security updatedebian
- unknownMultiple vulnerabilities in Google Chrome (July 15, 2026)cert-fr-avis
- mediumCVE-2026-15778: Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.…nvd
- highCVE-2026-15777: Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attack…nvd
- highCVE-2026-15776: Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote a…nvd
- mediumCVE-2026-15775: Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote a…nvd
- highCVE-2026-15774: Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who …nvd
- criticalCVE-2026-15773: Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote at…nvd
Recent advisories for Google Chrome
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Google Chrome: Multiple vulnerabilitiescert-bund · 2026-07-30
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert · 2026-07-30
- mediumCVE-2026-18019: Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a re…nvd · 2026-07-30
- mediumCVE-2026-18018: Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 all…nvd · 2026-07-30
- highCVE-2026-18017: Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to ex…nvd · 2026-07-30
- mediumCVE-2026-18016: Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.…nvd · 2026-07-30
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow unspecified attack2026-07-31