Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-13782: Google Chrome: Compromised browser can escape security sandbox
CVE-2026-13782 · published 3 months ago
Summary
A critical security risk was found in older versions of Google Chrome. If an attacker had already taken control of your browser, they could have used a specially crafted webpage to break out of the security features that keep them contained. Update your browser to the latest version to fix this issue.
What to do
- Update debian chromium to version 150.0.7871.46-1~deb13u1.
- Update google chrome to version 150.0.7871.46 or later.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:11 | debian | chromium | All versions |
| Debian:12 | debian | chromium | All versions |
| Debian:13 | debian | chromium |
< 150.0.7871.46-1~deb13u1 Fix: upgrade to 150.0.7871.46-1~deb13u1
|
| Debian:14 | debian | chromium | All versions |
| – | chrome |
< 150.0.7871.46 cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
Original advisory text
Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page....
Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
References
- https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_... Vendor Advisory
- https://issues.chromium.org/issues/516683433 Permissions Required
- https://security-tracker.debian.org/tracker/CVE-2026-13782 Vendor Advisory
Severity
10.0
Critical
CVSS 3.1: 10.0 (NVD)
CVSS 3.1: 10.0 (OSV)
Exploitation
EPSS <1%
Type
CWE-416Use After Free
Timeline
Published30 Jun 2026
Updated27 Sep 2026
First seen1 Jul 2026
Track software like this
Free during beta