CVE-2026-15903 is a high-severity vulnerability (CVSS 8.8) in the V8 JavaScript engine, discovered by OpenAI's GPT-5.6-Cyber model. It involves an out-of-bounds read and write that could allow remote attackers to execute arbitrary code inside a sandbox via a crafted HTML page. The flaw was patched by Google in mid-July 2026.