Junglewise Threat Intelligence

CVE-2026-13824: Google Chrome privilege escalation in Extensions

CVE-2026-13824 · Severity: info · CVSS 8.8 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the way Chrome handles browser extensions could allow a remote attacker to gain elevated privileges on a user's system. This could lead to unauthorized access to sensitive data or the ability to execute malicious commands if the attacker has already partially compromised the browser's rendering process.

Technical details

A privilege escalation vulnerability exists in the Extensions component of Google Chrome due to insufficient policy enforcement and improper validation of untrusted input. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass security boundaries. By utilizing a specially crafted HTML page, the attacker can escalate their privileges within the browser environment. This vulnerability is tracked as CVE-2026-13824 and was addressed in Chrome version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-05-14: disclosed: Reported by Google internal researchers
  • 2026-06-30: patched: Fixed in version 150.0.7871.47
  • 2026-06-30: advisory

References

Related threats