Junglewise Threat Intelligence

CVE-2026-13823: Google Chrome use after free in Glic

CVE-2026-13823 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its Glic component could allow a malicious website to bypass security protections (the sandbox) that normally isolate the browser from the rest of the computer. If exploited, an attacker who has already partially compromised the browser could gain broader access to the underlying system, potentially leading to data theft or unauthorized software installation.

Technical details

A use-after-free (UAF) vulnerability exists in the Glic component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the lifecycle of certain objects, allowing an attacker to reference memory after it has been freed. To exploit this, a remote attacker must first compromise the renderer process, typically through a separate vulnerability. Once the renderer is compromised, the attacker can use a specially crafted HTML page to trigger the UAF and achieve a sandbox escape, gaining elevated privileges on the host system. The issue is resolved in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-05-14: disclosed: Reported to Google internally
  • 2026-06-30: patched: Fixed in stable channel update 150.0.7871.47
  • 2026-06-30: advisory: CVE published

References

Related threats