SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-15108

MEDIUM · CVSS 4.3 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-08 · Last synced 2026-08-07

CyberRota Analysis

AI-Generated

An integer overflow vulnerability in the Extensions API of Google Chrome prior to version 150.0.7871.115 allows attackers to exploit a crafted extension to perform out-of-bounds memory reads. This could lead to unauthorized access to sensitive information or system compromise. Users and organizations utilizing affected versions of Chrome should prioritize updates to mitigate potential risks associated with this vulnerability.

CVE
CVE-2026-15108
Severity
MEDIUM
CVSS
4.3
EPSS
0.13%
Chrome

Original NVD Description

Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted Chrome Extension. (Chromium security severity: High)

Related CVEs

Other vulnerabilities affecting the same vendor(s)