Junglewise Threat Intelligence

CVE-2026-13792: Google Chrome use after free in Touchbar

CVE-2026-13792 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Chrome for macOS that affects the Touchbar functionality. By tricking a user into visiting a specially crafted website, a remote attacker could potentially bypass the browser's security sandbox. This could allow the attacker to gain unauthorized access to the underlying operating system or user data.

Technical details

A use-after-free (UAF) vulnerability exists in the Touchbar implementation of Google Chrome for macOS (CWE-416). The flaw is triggered when the browser incorrectly manages memory during the lifecycle of Touchbar-related objects. A remote attacker can exploit this by enticing a user to visit a malicious HTML page, leading to memory corruption. This corruption can be leveraged to achieve a sandbox escape, allowing code execution outside of the restricted browser environment. The issue is resolved in Google Chrome version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-03-25: disclosed: Reported by Weipeng Jiang (@Krace) of VRI
  • 2026-06-30: patched: Fixed in stable channel update 150.0.7871.47
  • 2026-06-30: advisory

References

Related threats