
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-15766 is an uninitialized use vulnerability in the Skia graphics rendering engine within Google Chrome, allowing a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. It was reported internally by Google on May 17, 2026, and publicly disclosed on July 14, 2026, as part of the Chrome 150 stable channel update. All Google Chrome versions prior to 150.0.7871.125 are affected. It carries a CVSS v3.1 base score of 6.5 (Medium) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-457 (Use of Uninitialized Variable) and resides in Chrome's Skia 2D graphics library, which handles rendering operations for web content. When processing a specially crafted HTML page, Skia reads from memory that has not been properly initialized, potentially exposing contents of the Chrome process memory to the attacker. Exploitation requires user interaction — specifically, a victim must visit a malicious or attacker-controlled web page — but no authentication or special privileges are required on the attacker's side. The Chromium issue tracker references bug ID 514010477 for this vulnerability (Chrome Releases, GitHub Advisory).
Successful exploitation results in a memory disclosure attack, where an unauthenticated remote attacker can read potentially sensitive data from the Chrome browser process memory. The confidentiality impact is rated High, while integrity and availability are unaffected. Exposed memory contents could include credentials, session tokens, cryptographic keys, or other sensitive data processed by the browser, potentially enabling further attacks or account compromise (GitHub Advisory).
Google has released a patch in Chrome stable channel version 150.0.7871.125 for Windows and Mac, and 150.0.7871.124 for Linux. Users and administrators should update Google Chrome to version 150.0.7871.125 or later immediately. As a temporary measure, users should avoid visiting untrusted or suspicious websites, and enterprise administrators can deploy browser security policies to restrict access to potentially malicious content. Chromium-based browsers (Edge, Brave, etc.) should also be updated as patches become available from their respective vendors (Chrome Releases, GitHub Advisory).
The Chrome 150 update, which includes the fix for CVE-2026-15766 alongside 14 other security fixes (including two Critical-rated use-after-free vulnerabilities), received coverage from security news outlets including CyberSecurityNews, GBHackers, and VPNcentral. The CIS also issued an advisory noting that multiple vulnerabilities in Google Chrome could allow for arbitrary code execution. No notable individual researcher commentary or significant social media discussion specific to CVE-2026-15766 has been identified, as the vulnerability is considered lower severity relative to the Critical issues patched in the same release (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."