CVE-2026-2315Patch(apple / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Inappropriate implementation in WebGPU in Google Chrome prior to 145.0.7632.45 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

1.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-12); latest day: 1
  • 6 total mentions across 3 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline6 mentions / 3d
01234Mentions · 2026-02-11: 1Mentions · 2026-02-12: 4Mentions · 2026-02-13: 1Patch / Workaround · 2026-02-12: 3Patch / Workaround · 2026-02-13: 1Technical Details · 2026-02-11: 1Technical Details · 2026-02-12: 3Technical Details · 2026-02-13: 102-1102-1202-13
Signal classification2 categories
Patch
466.7%
Disclosure
233.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-111
Disclosure1
2026-02-124
Disclosure1Patch3
2026-02-131
Patch1
Full discourse6 posts
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Google、Chrome 145のデスクトップ向け安定版で3件の重大な脆弱性を修正(CVE-2026-2313,CVE-2026-2314,CVE-2026-2315) https://rocket-boys.co.jp/security-measures-lab/google-chrome-145-desktop-fixes-three-critical-vulnerabilities-cve-2026-2313-cve-2026-2314-cve-2026-2315/ #セキュリティ対策Lab #セキュリティ #Security #CybersecurityNews

    Post summary

    Google Chrome 145 desktop stable version has been updated to fix three critical vulnerabilities (CVE-2026-2313, CVE-2026-2314, CVE-2026-2315), with no mention of PoC, exploitation, or technical details in the provided text.

    00011138
    318 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2315 WebGPU Out-of-Bounds Memory Access Vulnerability in Google Chrome https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2315

    Post summary

    The text announces a new WebGPU out-of-bounds memory access vulnerability in Google Chrome (CVE‑2026‑2315), providing minimal technical detail but no information on patches, exploits, or active attacks.

    0001049
    4.0K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Chrome 145 ships security update fixing 11 bugs, including 3 high-severity flaws Chrome 145 (145.0.7632.45/46) patches 11 vulnerabilities, including three high-severity issues: a CSS use-after-free (CVE-2026-2313), a heap buffer overflow in Codecs (CVE-2026-2314), and a WebGPU inappropriate implementation bug (CVE-2026-2315); Google says none are known to be exploited in the wild. Organizations should still push the update quickly given browser-bug exploitability and user exposure at scale. 🎯 Target: Global/Chrome Users #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.securityweek.com/chrome-145-patches-11-vulnerabilities/

    Post summary

    Chrome 145’s security update addresses 11 vulnerabilities, including three high‑severity issues (CVE‑2026‑2313, CVE‑2026‑2314, CVE‑2026‑2315), with no known wild exploitation, and urges prompt patching.

    0000040
    191 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Chrome 145 Security Update Patches 11 Bugs, Including High-Severity Code-Execution Flaws Google shipped Chrome 145 for Windows/macOS/Linux fixing 11 vulnerabilities, led by CVE-2026-2313 (high, use-after-free in CSS) plus CVE-2026-2314 (high, heap overflow in Codecs) and CVE-2026-2315 (high, WebGPU), all with potential code-execution impact. Users should update to 145.0.7632.45 (Linux) or 145.0.7632.45/46 (Windows/Mac) as the rollout progresses. 🎯 Target: Global / Chrome Users (Windows, macOS, Linux) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/chrome-security-update-patch-vulnerabilities/

    Post summary

    Google released Chrome 145, patching 11 high‑severity vulnerabilities (including CVE‑2026‑2313/2314/2315) that could lead to code execution, and urges users to update.

    00000108
    191 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    A `Chromium` `WebGPU` vulnerability (CVE-2026-2315) allows remote out-of-bounds memory access via crafted HTML. Monitor for patches. #Chromium #WebGPU #BrowserSecurity https://www.pulsepatch.io/posts/cve-2026-2315-chromium-webgpu-out-of-bounds

    Post summary

    The post announces CVE‑2026‑2315, a Chromium WebGPU flaw permitting remote out‑of‑bounds memory access via crafted HTML, and advises users to watch for vendor patches.

    0000042
    1 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Chrome 145 Emergency Update Fixes 11 High-Severity Browser Bugs Linked to Code Execution Risk Google shipped Chrome 145.0.7632.45 (announced Feb 10) patching 11 security flaws—including high-severity use-after-free and heap buffer overflow issues (e.g., CVE-2026-2313 in CSS, CVE-2026-2314 in Codecs, CVE-2026-2315 in WebGPU)—that could enable remote code execution or memory corruption via malicious content. This matters because browser RCE is a top initial-access path, so fast patch adoption reduces drive-by and phishing-delivered exploit success. 🎯 Target: Global / Chrome Users (Windows, macOS, Linux) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cyberpress.org/chrome-security-update-patches-vulnerabilities-2/

    Post summary

    Google released an emergency update Chrome 145 that patches 11 high‑severity bugs—including CVE‑2026‑2313, 2314, and 2315—addressing use‑after‑free and buffer overflow vulnerabilities that could allow remote code execution via malicious content.

    0000036
    191 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more