Junglewise Threat Intelligence

CVE-2026-13974: Google Chrome integer overflow in Safe Browsing

CVE-2026-13974 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Chrome for Mac within its Safe Browsing component, which is designed to protect users from malicious websites and files. A remote attacker could use a specially crafted file to bypass the browser's navigation restrictions, potentially leading users to unintended or harmful web locations. This issue has been addressed in the latest Chrome update, and users are advised to update to version 150.0.7871.47 or later.

Technical details

An integer overflow vulnerability (CWE-472) exists in the Safe Browsing component of Google Chrome for macOS. The flaw is triggered when the browser processes a malicious file, allowing a remote attacker to bypass established navigation restrictions. This could lead to the circumvention of security policies intended to block access to dangerous URLs. The vulnerability affected versions prior to 150.0.7871.47 and has been patched in the Stable Channel update. Exploitation requires the user to interact with a malicious file provided by the attacker.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats