Junglewise Threat Intelligence

CVE-2026-13911: Google Chrome insufficient policy enforcement in Spellcheck

CVE-2026-13911 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's spellcheck feature contained a security flaw that could allow a remote attacker to access sensitive information. If an attacker first compromises the browser's rendering process, they could use a specially crafted webpage to read data from the computer's memory. This could lead to the exposure of private user data or information from other open tabs.

Technical details

An information disclosure vulnerability exists in the Spellcheck component of Google Chrome due to insufficient policy enforcement. A remote attacker who has already achieved code execution within a compromised renderer process can exploit this flaw by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass memory isolation boundaries and read potentially sensitive information from the process memory. This vulnerability is addressed in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats