Junglewise Threat Intelligence

CVE-2026-13776: Google Chrome type confusion in Dawn

CVE-2026-13776 · Severity: info · CVSS 9.8 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical vulnerability exists in Google Chrome's Dawn component, which handles graphics processing. An attacker could use a specially crafted website to break out of the browser's security sandbox. If successful, this would allow the attacker to gain unauthorized access to the underlying operating system and sensitive user data.

Technical details

A type confusion vulnerability (CWE-843) exists in Dawn, the WebGPU implementation in Chromium. The flaw is reachable via a crafted HTML page. An attacker who has already compromised the renderer process can exploit this issue to achieve a sandbox escape, potentially leading to full system compromise. The vulnerability was reported by Google internal researchers and is addressed in Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-05-14: other: Reported by Google researchers
  • 2026-06-30: patched: Fixed in stable channel update 150.0.7871.47
  • 2026-06-30: disclosed

References

Related threats