Junglewise Threat Intelligence

CVE-2026-13778: Google Chrome use after free in WebUSB

CVE-2026-13778 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability exists in Google Chrome for Mac that could allow an attacker to take control of a computer. By connecting a specially crafted malicious USB device to the machine, an attacker can exploit a memory handling error to run unauthorized code. This could lead to the theft of sensitive data, installation of malware, or full system compromise.

Technical details

A use-after-free (UAF) vulnerability (CWE-416) exists in the WebUSB component of Google Chrome for macOS. The flaw is triggered when the browser incorrectly manages memory during interactions with USB peripherals. A local attacker with physical access or the ability to spoof a USB device can exploit this condition to achieve arbitrary code execution (ACE) within the context of the browser. The vulnerability was addressed in version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-05-14: disclosed: Reported to Google
  • 2026-06-30: patched: Fixed in version 150.0.7871.47
  • 2026-06-30: advisory

References

Related threats