
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-15767 is a heap buffer overflow vulnerability in the libyuv video processing library within Google Chrome on Windows. It allows a remote attacker to execute arbitrary code inside the Chrome sandbox by enticing a user to open a crafted video file. The vulnerability was reported internally by Google on 2026-05-19 and publicly disclosed on 2026-07-14 as part of the Chrome 150 stable channel update. All Chrome versions prior to 150.0.7871.125 on Windows are affected. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).
The root cause is a heap-based buffer overflow (CWE-122) in libyuv, the open-source library used by Chrome for YUV image and video format conversion. When Chrome processes a specially crafted video file, insufficient bounds checking in libyuv allows an attacker to write data beyond the allocated heap buffer, potentially corrupting adjacent memory. Exploitation requires user interaction — specifically, a victim must open or view the malicious video file — but no authentication or special privileges are required on the attacker's side. The vulnerability is tracked internally under Chromium issue 514748734 (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox on Windows systems. While sandbox containment limits the immediate blast radius, code execution within the renderer process can serve as a stepping stone for sandbox escape chains, potentially leading to full system compromise when combined with additional vulnerabilities. Confidentiality, integrity, and availability are all rated as high impact, meaning sensitive data accessible to the browser process could be exposed, browser state could be manipulated, and the browser process could be crashed or hijacked (GitHub Advisory).
.yuv, .webm, .mp4) from suspicious or newly registered domains.chrome.exe) spawning unexpected child processes or making unusual system calls on Windows; abnormal memory usage spikes in Chrome renderer processes during video playback.libyuv or video-related modules; crash dumps in %LOCALAPPDATA%\Google\Chrome\User Data\Crashpad\ referencing heap corruption.Google has released Chrome version 150.0.7871.125 for Windows and Mac (and 150.0.7871.124 for Linux) which addresses this vulnerability. Users should update Chrome immediately via the built-in update mechanism (Settings → Help → About Google Chrome). As a temporary workaround, users should avoid opening video files from untrusted sources and consider disabling video playback or restricting access to untrusted websites. Enterprise administrators can enforce Chrome version policies via Group Policy or Chrome Browser Cloud Management to ensure fleet-wide patching (Chrome Releases).
The Chrome 150 update, which includes CVE-2026-15767 among 15 security fixes (including two Critical-rated vulnerabilities), received coverage from security news outlets including CyberSecurityNews, GBHackers, SecurityOnline, and VPNcentral, which highlighted the breadth of the patch batch (CyberSecurityNews, GBHackers). The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Chrome could allow arbitrary code execution (CIS Advisory). Downstream Linux distributions including Debian, Fedora, and openSUSE also issued Chromium update advisories. No significant controversy or researcher-specific commentary on this individual CVE was observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."