Junglewise Threat Intelligence

CVE-2026-13835: Google Chrome heap corruption in XML implementation

CVE-2026-13835 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser for accessing internet resources. A security vulnerability in how the browser handles XML data could allow a malicious website to corrupt the browser's memory. If successfully exploited, this could lead to the browser crashing or potentially allow an attacker to gain unauthorized control over the user's application.

Technical details

A heap corruption vulnerability was identified in the XML component of Google Chrome. The issue stems from an inappropriate implementation in XML processing that can be triggered when a user visits a maliciously crafted HTML page. An attacker can exploit this by enticing a user to a remote website, leading to memory corruption. This is classified by Chromium as a High severity issue and could potentially lead to arbitrary code execution within the browser's sandbox. The vulnerability is addressed in Google Chrome version 150.0.7871.47 for Windows and Mac, and 150.0.7871.46 for Linux.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory: Google released the stable channel update fixing the issue.
  • 2026-06-30: disclosed: CVE published in NVD dataset.

References

Related threats