Junglewise Threat Intelligence

CVE-2026-13803: Google Chrome type confusion in Chrome Tabs

CVE-2026-13803 · Severity: info · CVSS 8.8 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Chrome's tab management system. If a user visits a specially crafted malicious website, an attacker who has already gained a foothold in the browser's rendering process could bypass security boundaries (the sandbox) that normally isolate websites from the rest of the computer. This could lead to unauthorized access to the underlying operating system and sensitive user data.

Technical details

This vulnerability is classified as a Type Confusion (CWE-843) within the Chrome Tabs component of Google Chrome. The flaw exists in versions prior to 150.0.7871.47. An attacker can exploit this by enticing a user to visit a malicious HTML page. If the attacker has already achieved code execution within the sandboxed renderer process, they can leverage this type confusion to escape the sandbox and execute arbitrary code on the host system. Google has addressed this issue in the stable channel update 150.0.7871.47 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-04-11: disclosed: Reported to Chromium by Google researchers.
  • 2026-06-30: patched: Fixed in Chrome version 150.0.7871.47.
  • 2026-06-30: advisory

References

Related threats