Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

CVE-2026-13783: Google Chrome: Malicious HTML can crash browser

CVE-2026-13783 · published 3 months ago
Summary

A security issue in Google Chrome before version 150.0.7871.47 allows an attacker to create a malicious web page that can potentially crash the browser. This can happen if a user is tricked into interacting with the page in a specific way. To stay safe, update to the latest version of Google Chrome.

What to do
  • Update google chrome to version 150.0.7871.46 or later.
Affected software
Ecosystem VendorProductAffected versions
Debian:14 debian chromium All versions
– google chrome < 150.0.7871.46
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Debian:11 debian chromium All versions
Debian:12 debian chromium All versions
Debian:13 debian chromium All versions
Original advisory text
Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted...
Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Severity
8.8 High
CVSS 3.1: 9.8 (NVD)
CVSS 3.1: 8.8 (OSV)
Exploitation
EPSS <1%
Type
CWE-416Use After Free
Timeline
Published30 Jun 2026
Updated27 Sep 2026
First seen1 Jul 2026
Sources
Track software like this
Free during beta