Junglewise Threat Intelligence

CVE-2026-13854: Google Chrome use after free in Ozone sandbox escape

CVE-2026-13854 · Severity: info · CVSS 8.8 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Chrome for Linux that could allow an attacker to bypass the browser's security sandbox. This occurs when a user visits a specially crafted malicious website. If successful, an attacker who has already compromised the browser's rendering process could gain broader access to the underlying operating system, potentially leading to unauthorized data access or full system compromise.

Technical details

A use-after-free (UAF) vulnerability exists in the Ozone abstraction layer of Google Chrome on Linux. The flaw is triggered when the browser improperly manages memory lifecycles within the Ozone component, which handles input and display hardware abstraction. An attacker who has already achieved remote code execution within a compromised renderer process can exploit this memory corruption to escape the Chrome sandbox. This requires the victim to navigate to a malicious HTML page. The vulnerability is addressed in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats