Junglewise Threat Intelligence

CVE-2026-13811: Google Chrome use after free in IME

CVE-2026-13811 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a security vulnerability in its Input Method Editor (IME) component. An attacker could exploit this by tricking a user into visiting a specially crafted website. If successful, the attacker could execute unauthorized code on the user's computer, though the impact is limited by the browser's security sandbox.

Technical details

A use-after-free vulnerability exists in the Input Method Editor (IME) component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of specific input sequences, allowing a remote attacker to achieve arbitrary code execution within the renderer sandbox. Exploitation requires the victim to navigate to a malicious, attacker-controlled HTML page. This issue was resolved in Google Chrome version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-04-24: disclosed: Reported to Chromium by Google researchers
  • 2026-06-30: patched: Fixed in stable channel update 150.0.7871.47
  • 2026-06-30: advisory

References

Related threats