Junglewise Threat Intelligence

CVE-2026-13864: Google Chrome privilege escalation in WebHID

CVE-2026-13864 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's WebHID component could allow a malicious browser extension to gain elevated privileges. To exploit this, an attacker must first trick a user into installing a specifically crafted extension. If successful, the attacker could bypass certain security restrictions within the browser, potentially compromising user data or browser stability.

Technical details

A privilege escalation vulnerability exists in the WebHID (Human Interface Device) implementation of Google Chrome. The flaw stems from insufficient policy enforcement, which fails to properly restrict the capabilities of browser extensions interacting with HID devices. An attacker can exploit this by convincing a user to install a malicious Chrome Extension. Once installed, the crafted extension can leverage the weak policy enforcement to escalate its privileges beyond the intended sandbox or permission model. This issue is resolved in Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats