Junglewise Threat Intelligence

CVE-2026-13848: Google Chrome use after free in Forms

CVE-2026-13848 · Severity: info · CVSS 8.8 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in the Google Chrome web browser's form-handling component. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially allowing the attacker to execute unauthorized code on the user's computer. While the impact is limited by the browser's security sandbox, it represents a significant risk to data privacy and system integrity.

Technical details

A use-after-free (UAF) vulnerability exists in the Forms component of Google Chrome prior to version 150.0.7871.47. The flaw is triggered when the browser incorrectly manages memory during the processing of HTML forms, allowing a remote attacker to achieve arbitrary code execution (ACE) within the Chromium sandbox. Exploitation requires a user to navigate to a malicious or compromised web page (User Interaction). Google has addressed this issue in the stable channel update 150.0.7871.47 for Windows, Mac, and Linux. The vulnerability is tracked as CWE-416.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats