Junglewise Threat Intelligence

CVE-2026-13875: Google Chrome improper input validation in GPU

CVE-2026-13875 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's GPU component could allow an attacker to access sensitive information from the browser's memory. This issue occurs when a user visits a specially crafted website, potentially exposing private data to an attacker who has already gained partial control over the browser's rendering process. Google has released an update to address this flaw.

Technical details

An improper input validation vulnerability (CWE-20) exists in the GPU component of Google Chrome on Windows. The flaw allows a remote attacker who has already compromised the renderer process to bypass security boundaries and read sensitive information from process memory. Exploitation requires the victim to navigate to a malicious HTML page. The vulnerability was addressed in Chrome version 150.0.7871.47.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats