Junglewise Threat Intelligence

CVE-2026-13805: Google Chrome use after free in GFX on Mac

CVE-2026-13805 · Severity: info · CVSS 8.8 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its graphics component (GFX) could allow a remote attacker to execute malicious code on a user's Mac computer if they visit a specially crafted website. This could lead to a full system compromise, unauthorized data access, or the installation of malware.

Technical details

A use-after-free (UAF) vulnerability exists in the GFX (graphics) component of Google Chrome on macOS. The flaw is triggered when the browser incorrectly manages memory during the rendering of specially crafted HTML content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, leading to arbitrary code execution within the context of the browser process. This vulnerability affects versions prior to 150.0.7871.47 and has been addressed in the Chrome 151 stable channel update.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-04-13: disclosed: Reported to Chromium by Google researchers
  • 2026-06-30: patched: Fixed in Chrome 150.0.7871.47 / Chrome 151 stable release
  • 2026-06-30: advisory

References

Related threats