CVE-2026-15905

Google · Chrome

A use after free vulnerability in the Aura component of Google Chrome allows a local attacker to potentially exploit heap corruption via a malicious file.

Executive summary

A local use after free vulnerability in Google Chrome could allow an attacker with local access to corrupt heap memory and potentially compromise the host system.

Vulnerability

This is a use after free vulnerability in the Aura component. An unauthenticated local attacker can exploit this flaw by providing a specially crafted file to the browser, leading to heap corruption.

Business impact

The CVSS score of 7.8 reflects a high risk for local environments. While the attack requires local access, the potential for heap corruption can lead to arbitrary code execution, resulting in privilege escalation or unauthorized data access on the affected system.

Remediation

Immediate Action: Update Google Chrome to version 150.0.7871.128 or later immediately.

Proactive Monitoring: Monitor local system logs for suspicious file access patterns or unexpected browser crashes that could indicate exploitation attempts.

Compensating Controls: Implement strict file permission controls and use endpoint security solutions to scan files for malicious indicators before they are opened by the browser.

Exploitation status

Public Exploit Available: False

Analyst recommendation

Organizations should treat this vulnerability as a high priority for local security. Applying the latest update to version 150.0.7871.128 is the only reliable way to close this memory management flaw and protect against local exploitation vectors.