Junglewise Threat Intelligence

CVE-2026-13903: Google Chrome privilege escalation in Bluetooth

CVE-2026-13903 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Bluetooth component could allow a remote attacker to gain elevated privileges on a user's system. By tricking a user into visiting a specially crafted website, an attacker could bypass security policies intended to restrict access to Bluetooth hardware. This could lead to unauthorized interaction with nearby devices or further compromise of the user's workstation.

Technical details

This vulnerability is classified as insufficient policy enforcement within the Web Bluetooth API implementation of Google Chrome. A remote attacker can exploit this by hosting a malicious HTML page that, when visited by a user, bypasses intended security restrictions to escalate privileges within the browser context. The flaw resides in how the browser validates or enforces access controls for Bluetooth resources. Google has addressed this issue in Chrome version 150.0.7871.47 and later. Access to specific bug details remains restricted to prevent further exploitation until a majority of users have updated.

Affected products

  • Google Chrome Prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats