CVE-2026-15112Patch(google / chrome)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch google chrome systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-07-09); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
chrome

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-07-09: 4Mentions · 2026-07-10: 1Mentions · 2026-07-13: 1Mentions · 2026-08-04: 1PoC Mentioned / Linked · 2026-07-09: 1Patch / Workaround · 2026-07-09: 4Patch / Workaround · 2026-07-10: 1Patch / Workaround · 2026-07-13: 1Technical Details · 2026-07-09: 2Technical Details · 2026-07-13: 1Technical Details · 2026-08-04: 107-0907-1007-1308-04
Signal classification2 categories
Patch
685.7%
Disclosure
114.3%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-07-094
Patch4
2026-07-101
Patch1
2026-07-131
Patch1
2026-08-041
Disclosure1
Full discourse7 posts
  • kokumօtօ@__kokumoto
    Patch

    Chromeでセキュリティ更新。27件の脆弱性が修正。うち2件(CVE-2026-15112, CVE-2026-15129)は重大(Critical)な解放後メモリ使用。公開PoC(攻撃の概念実証コード)や実際の悪用は未観測。 https://securityonline.info/chrome-security-update-27-fixes/

    Post summary

    Chrome's recent update fixed 27 vulnerabilities, including two critical use‑after‑free bugs (CVE-2026-15112, CVE-2026-15129). No public PoC or active exploitation has been observed, and the patches have been released.

    01020884
    7.7K followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #chrome Google が,Chrome 150.0.7871.114/.115 (Windows および Mac) および 150.0.7871.114 (Linux) をリリース. CVE ベースで 27 件(Critical 2 件  ・CVE-2026-15112  ・CVE-2026-15129 High 23 件)の脆弱性に対処. https://x.com/kawn2020/status/2075414551764537464

    Post summary

    Google released Chrome 150.0.7871.114/115 to patch 27 CVEs, including two critical ones.

    1000063
    90 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-15112: Google Chrome Ozone Use-After-Free Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04rRjv20

    Post summary

    The text announces the newly disclosed CVE-2026-15112, a Chrome Ozone use‑after‑free bug, and references a guide on the business impact and response steps.

    0000040
    32 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity CVE-2026-15112: Fedora 44 Chromium Use-After-Free Vulnerabilities — Detection a… "Fedora 44 users are facing a critical security requirement following the release of an…" 🔗 https://securityarsenal.com/blog/cve-2026-15112-fedora-44-chromium-use-after-free-vulnerabilities-detection-and-patching-guide #CyberSecurity #ThreatIntel #cve #zeroday #patchtuesday

    Post summary

    The post mainly highlights a blog that provides patching instructions for the Fedora 44 Chromium Use‑After‑Free CVE, with no PoC, exploit code, or evidence of active exploitation.

    0000092
    19 followersView on X
  • Cyberdark Impact@kenebeii
    Patch

    🔐 セキュリティトレンド (07:03 JST) ① Google Chrome、2件の最高深刻度を含む27件の脆弱性を修正-CVE-2026-15112 https://rocket-boys.co.jp/security-measures-lab/chrome-fixes-27-vulnerabilities-cve-2026-15112-15129/ ② 【速報】KDDI創業者の子4人、7億円超申告漏れ - 47NEWS https://www.47news.jp/14595813.html ③ 「快活」攻撃、18歳男逮捕 不正アクセス疑い、小学生も参加か - 北國新聞 https://www.hokkoku.co.jp/articles/-/2165168 ④ 「性的脅迫」メールが100通も届いた衝撃…「ニフティ」不正アクセスでPW漏れ186万人も https://toyokeizai.net/articles/-/950792 ⑤ 震度1 トカラ列島近海 2026年07月09日10:22ごろ 地震詳細 | 静岡のニュース | SBSNEWS https://newsdig.tbs.co.jp/list/sbs/bousai/earthquake/detail?event=20260709102249 #セキュリティ #CyberSecurity

    Post summary

    The news announces that Google Chrome has released a patch correcting 27 vulnerabilities, including CVE-2026‑15112, but provides no additional technical details or exploit information.

    00000483
    1.3K followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Google Chrome、2件の最高深刻度を含む27件の脆弱性を修正-CVE-2026-15112、CVE-2026-15129 https://rocket-boys.co.jp/security-measures-lab/chrome-fixes-27-vulnerabilities-cve-2026-15112-15129/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The post announces that Google Chrome has patched 27 vulnerabilities, including two high‑severity ones (CVE‑2026‑15112 and CVE‑2026‑15129), and provides a link to the vendor’s security information page.

    00000145
    462 followersView on X
  • TECHEPAGES@techepages
    Patch

    🚨 Chrome 150.0.7871.114/.115 ships fixes for 27 CVEs — 2 critical UAFs (CVE-2026-15112 in Ozone, CVE-2026-15129 in Views) enabling potential RCE. ⚠️ 22 high-severity bugs also patched across V8, WebRTC, Extensions API, ANGLE & Codecs — classic memory corruption territory. 🔹 UAF + heap grooming = exploit chain risk; patch before PoCs drop 🔹 Verify build via chrome://settings/help — forces update check & restart

    Post summary

    The tweet announces that Chrome 150.0.7871.114/.115 releases patches for 27 CVEs, including two critical UAFs that could enable RCE, urging users to update.

    00000108
    19 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---

Explore more