Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-13782: Google Chrome: Compromised browser can escape security sandbox

CVE-2026-13782 · published 3 months ago
Summary

A critical security risk was found in older versions of Google Chrome. If an attacker had already taken control of your browser, they could have used a specially crafted webpage to break out of the security features that keep them contained. Update your browser to the latest version to fix this issue.

What to do
  • Update debian chromium to version 150.0.7871.46-1~deb13u1.
  • Update google chrome to version 150.0.7871.46 or later.
Affected software
Ecosystem VendorProductAffected versions
Debian:11 debian chromium All versions
Debian:12 debian chromium All versions
Debian:13 debian chromium < 150.0.7871.46-1~deb13u1
Fix: upgrade to 150.0.7871.46-1~deb13u1
Debian:14 debian chromium All versions
– google chrome < 150.0.7871.46
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Original advisory text
Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page....
Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Severity
10.0 Critical
CVSS 3.1: 10.0 (NVD)
CVSS 3.1: 10.0 (OSV)
Exploitation
EPSS <1%
Type
CWE-416Use After Free
Timeline
Published30 Jun 2026
Updated27 Sep 2026
First seen1 Jul 2026
Sources
Track software like this
Free during beta