Junglewise Threat Intelligence

CVE-2026-13855: Google Chrome use after free in Ozone on Linux

CVE-2026-13855 · Severity: info · CVSS 8.8 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in the Google Chrome web browser for Linux that could allow a malicious website to execute unauthorized code on a user's computer. To trigger the issue, an attacker must trick a user into visiting a specially crafted webpage and performing specific mouse or keyboard interactions. If successful, this could lead to a complete compromise of the user's browser session and local data.

Technical details

A use-after-free (UAF) vulnerability exists in the Ozone abstraction layer of Google Chrome on Linux. The flaw is triggered when the browser incorrectly manages memory during specific UI gestures on a crafted HTML page. A remote attacker can exploit this by enticing a user to visit a malicious site and perform certain interactions, leading to arbitrary code execution within the context of the browser process. This issue is tracked as CWE-416 and was resolved in version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats