Junglewise Threat Intelligence

CVE-2026-13878: Google Chrome use after free in Bluetooth on macOS

CVE-2026-13878 · Severity: info · CVSS 6.5 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for macOS is a popular web browser. A vulnerability in its Bluetooth component could allow a remote attacker who has already partially compromised the browser to break out of its security sandbox. This could lead to unauthorized access to the underlying operating system and user data.

Technical details

A use-after-free (UAF) vulnerability exists in the Bluetooth component of Google Chrome for macOS (versions prior to 150.0.7871.47). The flaw is triggered when the browser incorrectly manages memory during Bluetooth-related operations. An attacker who has already compromised the renderer process (e.g., via a separate exploit) can leverage this vulnerability by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to escape the Chrome sandbox and execute code with the privileges of the browser process on the host operating system. The issue is tracked as CWE-416 and has been patched in version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory: NVD and Chrome Release blog published the vulnerability details.
  • 2026-06-30: patched: Fixed in Chrome version 150.0.7871.47 for Mac.

References

Related threats