Source status: Chrome's release notes directly credit OpenAI Codex Security on CVE-2026-15903 and CVE-2026-76045, and Duc Nguyen of Calif.io in collaboration with OpenAI Codex Security on CVE-2026-17658.
Summary
The three direct Chrome credits cover an out-of-bounds read/write in V8, a V8 use-after-free found with Calif.io, and a WebGL use-after-free. All three are classified High by Chrome.
Only release rows that name Codex Security are included. Neighboring Google- found CVEs and organization-only OpenAI credits are not inferred into the set.
References
- Chrome: July 16 stable update
- Chrome: July 2026 releases
- Chrome: August 2026 releases
- OpenAI: Codex Security research preview
Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.