Junglewise Threat Intelligence

CVE-2026-13815: Google Chrome use after free in Blink

CVE-2026-13815 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its Blink rendering engine allows a remote attacker to execute arbitrary code on a user's computer if they visit a specially crafted website. While the exploit is contained within the browser's security sandbox, it could be used as part of a larger attack to compromise the system or access sensitive user data.

Technical details

A use-after-free (UAF) vulnerability exists in the Blink rendering engine of Google Chrome prior to version 150.0.7871.47. The flaw is triggered when the browser incorrectly manages memory during the processing of HTML content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, leading to arbitrary code execution within the context of the browser's sandbox. This vulnerability was reported by Google internally and is addressed in the stable channel update to version 150.0.7871.47 and later.

Affected products

  • Google Chrome < 150.0.7871.47

Timeline

  • 2026-05-10: other: Reported to Chrome team
  • 2026-06-30: patched: Fixed in version 150.0.7871.47
  • 2026-06-30: disclosed

References

Related threats