[NEW] [high] Google Chrome: Multiple vulnerabilities allow unspecified attack
An attacker can exploit multiple vulnerabilities in Google Chrome to carry out an unspecified attack. Possible impacts include memory corruption, execution of arbitrary code, manipulation or disclosure of data, and triggering a denial-of-service state.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to carry out an unspecified attack, potentially leading to memory corruption and arbitrary code execution.
- Who is affected
- Users of Google Chrome.
- Urgency
- Remediation is urgent due to the high severity and potential for serious impacts including denial-of-service.
- Action
- Update Google Chrome to the latest version immediately.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Chrome
Get an email when a new Chrome advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2398
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-158990.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-159000.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-159010.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 18% of all scored CVEs.
- Low exploitation riskCVE-2026-159020.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all scored CVEs.
- Low exploitation riskCVE-2026-159030.31% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all scored CVEs.
- Low exploitation riskCVE-2026-159040.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all scored CVEs.
- Low exploitation riskCVE-2026-159050.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 1% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-15899 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15900 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15901 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15902 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15903 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15904 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-15905 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownDSA-6396-1 chromium - security updatedebian
- highCVE-2026-15905: Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to po…nvd
- highCVE-2026-15904: Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote att…nvd
- highCVE-2026-15903: Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote a…nvd
- highCVE-2026-15902: Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to e…nvd
- criticalCVE-2026-15901: Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker t…nvd
- criticalCVE-2026-15900: Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote att…nvd
- criticalCVE-2026-15899: Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remo…nvd
- unknownMicrosoft Edge Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Microsoft Edge (July 20, 2026)cert-fr-avis
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert
- unknownMultiple vulnerabilities in Google Chrome (July 17, 2026)cert-fr-avis
Recent advisories for Google Chrome
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] Google Chrome: Multiple vulnerabilitiescert-bund · 2026-07-30
- unknownGoogle Chrome Multiple Vulnerabilitieshkcert · 2026-07-30
- mediumCVE-2026-18019: Side-channel information leakage in Media in Google Chrome prior to 151.0.7922.72 allowed a re…nvd · 2026-07-30
- mediumCVE-2026-18018: Inappropriate implementation in Updater in Google Chrome on Windows prior to 151.0.7922.72 all…nvd · 2026-07-30
- highCVE-2026-18017: Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to ex…nvd · 2026-07-30
- mediumCVE-2026-18016: Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.…nvd · 2026-07-30
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel (ntfs3): Vulnerability allows information disclosure2026-07-31