Junglewise Threat Intelligence

CVE-2026-13873: Google Chrome out of bounds read in Layout

CVE-2026-13873 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the way the browser handles website layouts could allow a malicious website to read sensitive information from the browser's memory. This could potentially expose private data from other open tabs or browser processes to an attacker.

Technical details

An out-of-bounds read vulnerability exists in the Layout engine of Google Chrome prior to version 150.0.7871.47. The flaw is triggered when the browser processes a specially crafted HTML page, leading to memory access outside of intended buffers. A remote, unauthenticated attacker can exploit this to leak sensitive information from the browser's process memory. User interaction is required as a victim must visit a malicious website. The issue has been addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched: Fixed in version 150.0.7871.47

References

Related threats