Junglewise Threat Intelligence

CVE-2026-13861: Google Chrome use after free in Core

CVE-2026-13861 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome could allow a remote attacker to bypass security restrictions designed to isolate web pages from the rest of the computer. This 'sandbox escape' occurs if a user visits a specially crafted malicious website. If successful, an attacker who has already compromised the browser's rendering engine could gain broader access to the underlying system, potentially leading to data theft or further system compromise.

Technical details

A use-after-free (UAF) vulnerability exists in the Core component of Google Chrome prior to version 150.0.7871.47. The flaw is triggered when the browser incorrectly manages memory during the processing of HTML content. An attacker who has already achieved code execution within a compromised renderer process can exploit this memory corruption to escape the Chrome sandbox. This requires the victim to navigate to a malicious website. The issue is tracked as CWE-416 and has been addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats