Junglewise Threat Intelligence

CVE-2026-13961: Google Chrome improper input validation in DevTools

CVE-2026-13961 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's DevTools on Windows could allow a remote attacker to access sensitive information from the browser's memory. To exploit this, an attacker would need to trick a user into visiting a malicious website and performing specific mouse or keyboard actions. This could lead to the exposure of private data handled by the browser process.

Technical details

An improper input validation vulnerability (CWE-20) exists in the DevTools component of Google Chrome for Windows. The flaw allows a remote attacker to bypass memory protections and read sensitive information from the browser's process memory. Exploitation requires the attacker to host a specially crafted HTML page and successfully convince a user to perform specific UI gestures (user interaction). This issue was addressed in Chrome version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats