Junglewise Threat Intelligence

CVE-2026-13774: Google Chrome use after free in Extensions

CVE-2026-13774 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome's extension system. If a user is tricked into installing a malicious extension, an attacker could gain the ability to execute unauthorized code on the user's computer. This could lead to a total compromise of the device, including the theft of sensitive data or the installation of further malware.

Technical details

A use-after-free (UAF) vulnerability exists in the Extensions framework of Google Chrome prior to version 150.0.7871.47. The flaw is triggered when the browser incorrectly manages memory during the operation of a crafted Chrome Extension. An attacker must convince a user to install a malicious extension to exploit this vulnerability. Successful exploitation allows for arbitrary code execution within the context of the browser, potentially escaping the sandbox depending on other system factors. Google has addressed this in the stable channel update to version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-04-26: disclosed: Reported by Google internally
  • 2026-06-30: patched: Fixed in Chrome 150.0.7871.47 stable channel update
  • 2026-06-30: advisory

References

Related threats