Multiple Vulnerabilities in Google Chrome Enable Remote Code Execution and Information Disclosure (CVE-2026-15899 through CVE-2026-15905) — Threadlinqs Intelligence
As of 2026-07-18, Multiple Vulnerabilities in Google Chrome Enable Remote Code Execution and Information Disclosure (CVE-2026-15899 through CVE-2026-15905) is a high-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-1501 · Severity: HIGH · Status: ACTIVE · Category: VULNERABILITY
Google shipped Chrome 150.0.7871.128/.129 for Windows/Mac and 150.0.7871.128 for Linux on 2026-07-16, patching seven vulnerabilities (three Critical, four High) spanning CameraCapture, GPU, Network,
On 2026-07-16 the Google Chrome team published a stable channel update raising the desktop release to version 150.0.7871.128 (Windows/Mac also received a parallel 150.0.7871.129 build) and 150.0.7871.128 for Linux, rolling out over subsequent days/weeks via Chrome's auto-update mechanism. The release addresses seven vulnerabilities tracked as CVE-2026-15899 through CVE-2026-15905, three of which Google rates Critical and four of which are rated High. The three Critical issues are use-after-free (UAF) memory-corruption bugs in the CameraCapture subsystem (CVE-2026-15899, reported internally 2026-05-27), the GPU process (CVE-2026-15900, reported internally 2026-06-14 — the GPU process manages hardware-accelerated compositing, WebGL, video decode, and canvas rendering, making it reachable from ordinary web content), and the Network stack (CVE-2026-15901, reported to Google 2026-07-10) — all classes of bug that historically underpin renderer or GPU-process remote code execution chains reachable from a single malicious web page, frequently combined with a second bug (sandbox escape or type confusion) for full system compromise. The four High-severity issues comprise a use-after-free in Cast (CVE-2026-15902, reported 2026-06-10), an out-of-bounds read AND write flaw in the V8 JavaScript engine (CVE-2026-15903, reported by external researcher 'amyb' of OpenAI Codex Security on 2026-07-06 — an OOB read/write primitive in V8 is a classic building block for constructing an arbitrary read/write capability inside the renderer sandbox), an issue in the Ozone platform abstraction layer used by Linux/ChromeOS builds (CVE-2026-15904), and a use-after-free in Aura, the cross-platform windowing/compositing system (CVE-2026-15905). GovCERT.HK (Hong Kong Government Computer Emergency Response Team) issued Security Alert A26-07-31 on 2026-07-17, characterizing overall severity as High and warning that "a remote attacker could entice a user to open a web page with specially crafted content" to trigger RCE or information disclosure — the classic Chrome drive-by exploitation pattern: victim navigation/click is the only user interaction required, no attachment or download involved. HKCERT published a parallel bulletin the same day, and France's CERT-FR (ANSSI) issued advisory CERTFR-2026-AVI-0897 on 2026-07-17 covering the identical CVE set, indicating multi-national government CERT coordination/dissemination of this advisory within 24 hours of the vendor patch. As of this research (2026-07-18) neither the CISA Known Exploited Vulnerabilities (KEV) catalog nor Google's own advisory language indicate confirmed in-the-wild exploitation; Google's release notes for this cycle do not carry Google's standalone "exploit exists in the wild" caveat that accompanies actively-exploited 0-days, and none of CVE-2026-15899 through CVE-2026-15905 appear in the CISA KEV feed as of the alert date. Consistent with Google's standard disclosure practice, technical bug-tracker details for all seven CVEs remain access-restricted until a majority of the Chrome user base has installed the fix, to slow adversary reverse-engineering of a working exploit from the patch diff (a well-documented Chrome n-day risk window). Exploitability is therefore assessed as POC_PUBLIC/plausible-but-unconfirmed rather than confirmed active exploitation, and the advisory should be treated as a preventive high-priority patch rather than an active-incident notification. Because most of the fixed classes are use-after-free bugs, the standard Chrome UAF exploitation chain applies: an attacker-controlled web page triggers a dangling-pointer condition in the vulnerable component (CameraCapture, GPU, Cast, Aura), reclaims the freed memory with attacker-controlled data via heap grooming/spraying (JS typed arrays, ArrayBuffers, or WebGL/Canvas objects), and pivots the corrupted vtable/object state into arbitrary read/write and ultimately code execution inside the renderer or GPU process; the V8 OOB read/
Weaknesses (CWE)
CWE-416, CWE-843, CWE-125, CWE-787
Target sectors: all sectors general chrome user base, government administration, enterprise, critical-infrastructure, education, health, finance
Target regions: Global, hong kong, france
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, HIGH, threat intelligence, cybersecurity, CVE-2026-15899, CVE-2026-15900, CVE-2026-15901, CVE-2026-15902, CVE-2026-15903, CVE-2026-15904, CVE-2026-15905, T1593, T1587, T1588, T1584, T1189, T1566, T1566, T1203, T1176, T1068