Junglewise Threat Intelligence

CVE-2026-13968: Google Chrome improper input validation in DevTools

CVE-2026-13968 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its developer tools (DevTools) could allow a remote attacker to execute malicious code on a user's computer if they are tricked into performing specific interactions with a malicious file. While the code execution is restricted within a security sandbox, it still represents a significant risk to the integrity of the user's browsing session.

Technical details

An improper input validation vulnerability (CWE-20) exists in the DevTools component of Google Chrome. The flaw is triggered when the application fails to sufficiently validate untrusted input from a malicious file. A remote attacker can exploit this by convincing a user to perform specific UI gestures, leading to arbitrary code execution within the browser's sandbox environment. The vulnerability was addressed in version 150.0.7871.47. Access to further technical details is currently restricted by the Chromium team until a majority of users have updated.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats