CVE-2026-15776
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a san
CVSS
8.8
High
EPSS
0.3%
p25
KEV
—
Exploit Today
8
0-100
Published: Jul 14, 2026 · Last modified: Jul 15, 2026 · CWE-843
0.3%EPSS · 30 days0.3%
2026-07-152026-07-21
Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-646089.8 CRI—
——0Heap type confusion and out-of-bounds read/write in the Apache Fory C++ implementation. When deserializing data in compatible mode, the field-skip paths do not correctly validate the declared field types against the actual data, so input with an inconsistent schema can cause type confusion and out-of-bounds memory access. Only the C++ implementation is affected; other language implementations of Apache Fory are not.
This issue affects Apache Fory C++: from 0.14.0 before 1.4.0.
Users are recommended to upgrade to version 1.4.0, which fixes the issue.3hCVE-2026-585417.8 HIG21.0%
——6Access of resource using incompatible type ('type confusion') in Windows DWM allows an authorized attacker to elevate privileges locally.5dCVE-2026-571087.5 HIG61.3%
——18Access of resource using incompatible type ('type confusion') in .NET Core allows an unauthorized attacker to deny service over a network.1dCVE-2026-550257.8 HIG22.4%
——7Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.6dCVE-2026-550247.8 HIG31.6%
——9Access of resource using incompatible type ('type confusion') in Microsoft Office Excel allows an unauthorized attacker to execute code locally.6dCVE-2026-550227.8 HIG30.0%
——9Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.5d