Junglewise Threat Intelligence

CVE-2026-16805: Google Chrome use after free in Blink

CVE-2026-16805 · Severity: info · Published 2026-07-23

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its Blink rendering engine could allow a malicious website to execute unauthorized code on a user's computer. While the attack is limited by the browser's security sandbox, it could still lead to service disruptions or be used as part of a larger attack to compromise the system.

Technical details

A use-after-free (UAF) vulnerability exists in the Blink rendering engine of Google Chrome prior to version 150.0.7871.186. The flaw is triggered when the browser incorrectly manages memory during the processing of specially crafted HTML content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious website, leading to arbitrary code execution (ACE) within the context of the browser's sandboxed process. This vulnerability is tracked as CWE-416. Users are advised to update to version 150.0.7871.186 or later to mitigate the risk.

Affected products

  • Google Chrome prior to 150.0.7871.186

Timeline

  • 2026-06-12: other: Reported to Google
  • 2026-07-23: patched: Fixed in version 150.0.7871.186/.187
  • 2026-07-23: disclosed: Public advisory released

References

Related threats