Junglewise Threat Intelligence

CVE-2026-13817: Google Chrome improper input validation in Glic

CVE-2026-13817 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's Glic component. An attacker could use a specially crafted website to bypass the browser's security sandbox, which is designed to keep malicious code from affecting the rest of the computer. This could lead to unauthorized access to the underlying operating system or user data.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Glic component of Google Chrome. By convincing a user to visit a specially crafted HTML page, a remote attacker can exploit insufficient validation of untrusted input to perform a sandbox escape. This allows code execution outside of the restricted browser process environment. The vulnerability is addressed in Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-05-10: other: Reported to Google
  • 2026-06-30: patched: Fixed in stable channel update 150.0.7871.47
  • 2026-06-30: disclosed: Public advisory published

References

Related threats