Junglewise Threat Intelligence

CVE-2026-13802: Google Chrome use after free in Views

CVE-2026-13802 · Severity: info · CVSS 8.8 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, was found to have a security flaw in its 'Views' component, which handles the visual layout of the browser interface. An attacker could exploit this by tricking a user into visiting a malicious website and performing specific mouse or keyboard actions. If successful, this could allow the attacker to take control of the browser or execute unauthorized commands on the user's computer.

Technical details

A use-after-free (UAF) vulnerability exists in the Views component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory for UI elements, allowing a remote attacker to potentially execute arbitrary code in the context of the browser process. Exploitation requires the attacker to host a specially crafted HTML page and successfully entice a user to perform specific UI gestures (such as clicking or dragging). This vulnerability was addressed in Chrome version 150.0.7871.47 for Windows and Mac, and 150.0.7871.46 for Linux.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-04-11: disclosed: Reported to Chromium by Google internal researchers
  • 2026-06-30: advisory: Public advisory published by Google Chrome team
  • 2026-06-30: patched: Fixed in stable channel update 150.0.7871.47

References

Related threats