Junglewise Threat Intelligence

CVE-2026-13791: Google Chrome improper input validation in Downloads

CVE-2026-13791 · Severity: info · CVSS 8.8 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a security vulnerability in its download management component. If a user was persuaded to install a malicious browser extension, an attacker could use this flaw to take control of the user's computer and execute unauthorized commands. This could lead to the theft of sensitive personal data, installation of further malware, or complete system compromise.

Technical details

An improper input validation vulnerability (CWE-20) existed in the Downloads component of Google Chrome prior to version 150.0.7871.47. The flaw allowed a crafted Chrome Extension to bypass security boundaries when handling untrusted input. An attacker could exploit this by convincing a user to install a malicious extension, subsequently achieving arbitrary code execution on the host system. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-04-17: disclosed: Reported by Ron Masas (Imperva)
  • 2026-06-30: patched: Fixed in version 150.0.7871.47 / 151.0.x
  • 2026-06-30: advisory

References

Related threats