CVE-2026-15767
Google Chrome vulnerability analysis and mitigation

Overview

CVE-2026-15767 is a heap buffer overflow vulnerability in the libyuv video processing library within Google Chrome on Windows. It allows a remote attacker to execute arbitrary code inside the Chrome sandbox by enticing a user to open a crafted video file. The vulnerability was reported internally by Google on 2026-05-19 and publicly disclosed on 2026-07-14 as part of the Chrome 150 stable channel update. All Chrome versions prior to 150.0.7871.125 on Windows are affected. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).

Technical details

The root cause is a heap-based buffer overflow (CWE-122) in libyuv, the open-source library used by Chrome for YUV image and video format conversion. When Chrome processes a specially crafted video file, insufficient bounds checking in libyuv allows an attacker to write data beyond the allocated heap buffer, potentially corrupting adjacent memory. Exploitation requires user interaction — specifically, a victim must open or view the malicious video file — but no authentication or special privileges are required on the attacker's side. The vulnerability is tracked internally under Chromium issue 514748734 (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox on Windows systems. While sandbox containment limits the immediate blast radius, code execution within the renderer process can serve as a stepping stone for sandbox escape chains, potentially leading to full system compromise when combined with additional vulnerabilities. Confidentiality, integrity, and availability are all rated as high impact, meaning sensitive data accessible to the browser process could be exposed, browser state could be manipulated, and the browser process could be crashed or hijacked (GitHub Advisory).

Exploitation steps

  1. Craft malicious video file: Create a specially crafted video file (e.g., in a YUV-based format such as WebM or MP4) that triggers the heap buffer overflow in libyuv during color space conversion or frame processing.
  2. Host or deliver the payload: Host the malicious video file on an attacker-controlled web server, or embed it in a webpage, email attachment, or document that will be opened in Chrome on Windows.
  3. Social engineering: Lure the target user into visiting the malicious URL or opening the crafted file in Chrome (e.g., via phishing email, malicious advertisement, or compromised website).
  4. Trigger the overflow: When Chrome's libyuv processes the video file, the heap buffer overflow is triggered, corrupting adjacent heap memory in the renderer process.
  5. Achieve sandbox code execution: Leverage the memory corruption to gain control of the renderer process execution flow, achieving arbitrary code execution within the Chrome sandbox.
  6. Optional sandbox escape: Chain with an additional privilege escalation or sandbox escape vulnerability to move beyond the Chrome sandbox and achieve broader system access (Chrome Releases).

Indicators of compromise

  • Network: Unusual outbound connections from the Chrome renderer process to unknown external IPs; HTTP/HTTPS requests to domains serving unexpected video file types (e.g., .yuv, .webm, .mp4) from suspicious or newly registered domains.
  • Process: Chrome renderer processes (chrome.exe) spawning unexpected child processes or making unusual system calls on Windows; abnormal memory usage spikes in Chrome renderer processes during video playback.
  • Logs: Windows Event Logs showing Chrome crashes or application faults (Event ID 1000/1001) referencing libyuv or video-related modules; crash dumps in %LOCALAPPDATA%\Google\Chrome\User Data\Crashpad\ referencing heap corruption.
  • File System: Unexpected files written to the user's temp directory or Chrome profile directory by the renderer process; presence of downloaded video files from untrusted sources in browser download history.

Mitigation and workarounds

Google has released Chrome version 150.0.7871.125 for Windows and Mac (and 150.0.7871.124 for Linux) which addresses this vulnerability. Users should update Chrome immediately via the built-in update mechanism (Settings → Help → About Google Chrome). As a temporary workaround, users should avoid opening video files from untrusted sources and consider disabling video playback or restricting access to untrusted websites. Enterprise administrators can enforce Chrome version policies via Group Policy or Chrome Browser Cloud Management to ensure fleet-wide patching (Chrome Releases).

Community reactions

The Chrome 150 update, which includes CVE-2026-15767 among 15 security fixes (including two Critical-rated vulnerabilities), received coverage from security news outlets including CyberSecurityNews, GBHackers, SecurityOnline, and VPNcentral, which highlighted the breadth of the patch batch (CyberSecurityNews, GBHackers). The Center for Internet Security (CIS) issued an advisory noting that multiple vulnerabilities in Chrome could allow arbitrary code execution (CIS Advisory). Downstream Linux distributions including Debian, Fedora, and openSUSE also issued Chromium update advisories. No significant controversy or researcher-specific commentary on this individual CVE was observed.

Additional resources


SourceThis report was generated using AI

Related Google Chrome vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16807HIGH8.8
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesJul 23, 2026
CVE-2026-16806HIGH8.8
  • Google Chrome logoGoogle Chrome
  • chromium
NoYesJul 23, 2026
CVE-2026-16805HIGH8.8
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesJul 23, 2026
CVE-2026-16804HIGH8.3
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesJul 23, 2026
CVE-2026-15770MEDIUM6.5
  • Google Chrome logoGoogle Chrome
  • chromium-common
NoYesJul 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management