CVE-2026-15129Patch(google / chrome)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch google chrome systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 4 mentions (2026-07-09); latest day: 1
  • 7 total mentions across 4 days

Affected systems

Vendors
Products
chrome

Deep dive

Activity timeline7 mentions / 4d
01234Mentions · 2026-07-09: 4Mentions · 2026-07-10: 1Mentions · 2026-08-04: 1Mentions · 2026-08-09: 1PoC Mentioned / Linked · 2026-07-09: 1Patch / Workaround · 2026-07-09: 3Patch / Workaround · 2026-07-10: 1Patch / Workaround · 2026-08-09: 1Technical Details · 2026-07-09: 2Technical Details · 2026-08-04: 107-0907-1008-0408-09
Signal classification3 categories
Patch
571.4%
General
114.3%
Disclosure
114.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-07-094
General1Patch3
2026-07-101
Patch1
2026-08-041
Disclosure1
2026-08-091
Patch1
Full discourse7 posts
  • kokumօtօ@__kokumoto
    Patch

    Chromeでセキュリティ更新。27件の脆弱性が修正。うち2件(CVE-2026-15112, CVE-2026-15129)は重大(Critical)な解放後メモリ使用。公開PoC(攻撃の概念実証コード)や実際の悪用は未観測。 https://securityonline.info/chrome-security-update-27-fixes/

    Post summary

    Chrome released a security update fixing 27 vulnerabilities, two of which are critical use‑after‑free CVEs (CVE‑2026‑15112 & CVE‑2026‑15129) for which a public PoC exists but no active exploitation has been observed.

    01020884
    7.7K followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #chrome Google が,Chrome 150.0.7871.114/.115 (Windows および Mac) および 150.0.7871.114 (Linux) をリリース. CVE ベースで 27 件(Critical 2 件  ・CVE-2026-15112  ・CVE-2026-15129 High 23 件)の脆弱性に対処. https://x.com/kawn2020/status/2075414551764537464

    Post summary

    Google released Chrome 150.0.7871.114/115 with patches for 27 CVEs, including CVE-2026-15112 and CVE-2026-15129, emphasizing the update rather than exploitation or technical details.

    1000063
    90 followersView on X
  • kawn@kawn2020
    Patch

    #securityupdate #chromeos Google が LTS-144 バージョンとして ChromeOS 144.0.7559.258 (Platform Version: 16503.91.0) をリリース. CVE ベースで Critical 4 件 ・CVE-2026-8513 ・CVE-2026-10888 ・CVE-2026-15129 ・CVE-2026-15765 High 23 件,Medium 1 件に対処. https://x.com/kawn2020/status/2086284993714926054

    Post summary

    Google released a new ChromeOS LTS version that patches 4 critical CVEs, 23 high‑severity, and 1 medium‑severity issue, demonstrating a patch update to secure the OS.

    0000059
    90 followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-15129: Google Chrome Use-After-Free Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04rT9bP0

    Post summary

    The brief description indicates a new use‑after‑free vulnerability in Google Chrome but offers no further details on PoC, exploitation, or remediation.

    0000048
    32 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Google Chrome、2件の最高深刻度を含む27件の脆弱性を修正-CVE-2026-15112、CVE-2026-15129 https://rocket-boys.co.jp/security-measures-lab/chrome-fixes-27-vulnerabilities-cve-2026-15112-15129/ #セキュリティ対策Lab #security #securitynews

    Post summary

    A security article reports that Google Chrome has released patches for 27 vulnerabilities, including CVE‑2026‑15112 and CVE‑2026‑15129, signaling that fixes are now available.

    00000145
    462 followersView on X
  • TECHEPAGES@techepages
    Patch

    🚨 Chrome 150.0.7871.114/.115 ships fixes for 27 CVEs — 2 critical UAFs (CVE-2026-15112 in Ozone, CVE-2026-15129 in Views) enabling potential RCE. ⚠️ 22 high-severity bugs also patched across V8, WebRTC, Extensions API, ANGLE & Codecs — classic memory corruption territory. 🔹 UAF + heap grooming = exploit chain risk; patch before PoCs drop 🔹 Verify build via chrome://settings/help — forces update check & restart

    Post summary

    Chrome 150.0.7871.114/.115 includes fixes for 27 CVEs, notably two critical use‑after‑free bugs that could lead to remote code execution; users are urged to update immediately.

    00000108
    19 followersView on X
  • VulDB 🛡@vuldb
    General

    A severe vulnerability was disclosed for Google Chrome (CVE-2026-15129) https://vuldb.com/vuln/377083

    Post summary

    A severe vulnerability, CVE-2026-15129, affecting Google Chrome has been disclosed, but the provided text offers no further technical information, exploitation details, or remedial guidance.

    00000114
    2.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---

Explore more