All findings

CVE-2026-15903, CVE-2026-17658, CVE-2026-76045 high

Chrome directly credits Codex Security on three new high-severity CVEs

Chrome's July and August releases directly name OpenAI Codex Security on V8 and WebGL memory-safety vulnerabilities.

Bug class
Out-of-bounds access and use-after-free in browser execution and graphics engines
Affected codebase
Chromium V8 and WebGL
Credited system
OpenAI Aardvark / Codex Security
Disclosed
August 18, 2026
Attribution
Direct source attribution
Severity
high
Source status: Chrome's release notes directly credit OpenAI Codex Security on CVE-2026-15903 and CVE-2026-76045, and Duc Nguyen of Calif.io in collaboration with OpenAI Codex Security on CVE-2026-17658.

Summary

The three direct Chrome credits cover an out-of-bounds read/write in V8, a V8 use-after-free found with Calif.io, and a WebGL use-after-free. All three are classified High by Chrome.

Only release rows that name Codex Security are included. Neighboring Google- found CVEs and organization-only OpenAI credits are not inferred into the set.


References


Catalogued in the Bugflation public ledger. Disagree with the attribution or severity label? Email the desk.