Junglewise Threat Intelligence

CVE-2026-16806: Google Chrome use after free in WebMCP

CVE-2026-16806 · Severity: info · Published 2026-07-23

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's WebMCP component. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially allowing the attacker to run unauthorized code on the user's computer. While the exploit is limited by Chrome's security sandbox, it still poses a significant risk to system integrity and user data.

Technical details

A use-after-free (UAF) vulnerability exists in the WebMCP component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of a crafted HTML page, allowing a remote attacker to potentially execute arbitrary code. While the execution is confined within the Chrome sandbox, it represents a significant step in a multi-stage exploit chain. The vulnerability is addressed in Google Chrome version 150.0.7871.186 and later. The issue was identified as CWE-416.

Affected products

  • Google Chrome prior to 150.0.7871.186

Timeline

  • 2026-06-10: other: Reported to Google
  • 2026-07-23: patched: Fixed in stable channel update 150.0.7871.186
  • 2026-07-23: disclosed

References

Related threats