Junglewise Threat Intelligence

CVE-2026-13028: Google Chrome use after free in WebGL

CVE-2026-13028 · Severity: info · CVSS 9.8 · Published 2026-06-24

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in the Google Chrome web browser's WebGL component, which handles 3D graphics. By tricking a user into visiting a specially crafted website, a remote attacker could bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system, potentially leading to data theft or the installation of malicious software.

Technical details

A use-after-free (UAF) vulnerability exists in the WebGL implementation of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the rendering of 3D graphics content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious webpage containing crafted HTML and WebGL instructions. Successful exploitation can lead to a sandbox escape, allowing the attacker to execute arbitrary code outside of the browser's restricted environment. This issue was addressed in Chrome version 149.0.7827.196/197.

Affected products

  • Google Chrome Prior to 149.0.7827.196/197

Timeline

  • 2026-06-07: disclosed: Reported by anonymous researcher
  • 2026-06-23: patched: Stable channel update released
  • 2026-06-24: advisory: NVD publication date

References

Related threats