CVE-2026-15113Disclosure(google / android)

LOWCVSS 9.6 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch google android systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android
  • chrome

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
androidchrome

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-07-09: 3Patch / Workaround · 2026-07-09: 1Technical Details · 2026-07-09: 307-09
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 CRITICAL - Chrome Android Autofill use-after-free sandbox escape (CVE-2026-15113) A use-after-free vulnerability exists in the Autofill component of Google Chrome on Android prior to 150.0.7871.115, triggered during HTML-driven form/autofill handling. The root cause is a use-after-free memory safety flaw where an object is freed and later reused, enabling memory corruption. An attacker can exploit this remotely by luring a user to a crafted HTML page that manipulates Autofill behavior, requiring no special privileges beyond user interaction (page visit). Successful exploitation could allow sandbox escape and potentially lead to arbitrary code execution in a more privileged context, enabling device compromise, data theft, or further exploitation chains. 👉 Affected: Google Chrome for Android < 150.0.7871.115 | Upgrade to 150.0.7871.115

    Post summary

    Chrome for Android before 150.0.7871.115 has a use‑after‑free flaw in Autofill that could enable sandbox escape via a crafted HTML page; users are advised to upgrade to the fixed version.

    00010115
    246 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-15113 Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML pa… https://www.cve.org/CVERecord?id=CVE-2026-15113 ----- Traducción: CVE-2026-15113 Use… http://infoflow.cloud`

    Post summary

    The text discloses a use‑after‑free flaw in Chrome’s Autofill on Android (pre‑150.0.7871.115) that could allow sandbox escape, with no PoC, exploit, patch, or active exploitation information provided.

    0000046
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-15113 Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML pa… https://www.cve.org/CVERecord?id=CVE-2026-15113

    Post summary

    CVE-2026-15113 is a use‑after‑free flaw in Google Chrome’s Autofill on Android that could lead to sandbox escape via crafted HTML; no evidence of patches or active exploitation is mentioned.

    00000709
    57.8K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid---
Appgooglechrome---

Explore more