Junglewise Threat Intelligence

CVE-2026-13810: Google Chrome inappropriate implementation in Input

CVE-2026-13810 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Linux is a popular web browser used for accessing the internet and running web applications. A security flaw in the browser's input handling component could allow a malicious website to access sensitive information stored in the computer's memory. This could lead to the exposure of private data such as login credentials or browsing history from other open tabs or processes.

Technical details

An information disclosure vulnerability exists in the Input component of Google Chrome for Linux. The flaw is characterized as an 'inappropriate implementation' that allows for an out-of-bounds memory read or similar side-channel leakage. A remote, unauthenticated attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to read sensitive data from the browser's process memory. The issue is resolved in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-04-20: disclosed: Reported to Chromium by dilipsc03@gmail.com
  • 2026-06-30: patched: Fixed in stable channel update 150.0.7871.47 for Linux
  • 2026-06-30: advisory: NVD publication date

References

Related threats