CVE-2026-13035
published 2026-06-24CVE-2026-13035: Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a malicious peripheral…
PriorityP353high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.22%
12.2th percentile
Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: High)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 149.0.7827.197 | 149.0.7827.197 | |
| chrome | >= 149.0.7827.197 < 149.0.7827.197 | 149.0.7827.197 | |
| chrome_desktop | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a malicious peripheral.
ghsa_unreviewed·2026-06-24
CVE-2026-13035 [HIGH] CWE-416 Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a malicious peripheral.
Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: High)
VulDB
Google Chrome up to 149.0.7827.155 on macOS Bluetooth use after free (ID 523704)
vuldb·2026-06-24·CVSS 8.8
CVE-2026-13035 [HIGH] Google Chrome up to 149.0.7827.155 on macOS Bluetooth use after free (ID 523704)
A vulnerability identified as critical has been detected in Google Chrome on macOS. This affects an unknown part of the component Bluetooth. The manipulation leads to use after free.
This vulnerability is traded as CVE-2026-13035. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
Chrome
Stable Channel Update for Desktop: CVE-2026-13035
vendor_chrome·2026-06-23
CVE-2026-13035 [HIGH] Stable Channel Update for Desktop: CVE-2026-13035
Stable Channel Update for Desktop
CVE-2026-13035: Use after free in Bluetooth. Reported by Google on 2026-06-13 [N/A][ 523711130 ] High CVE-2026-13036: Use after free in Blink
Reported by Google on 2026-06-13 [N/A][ 523721871 ] High CVE-2026-13037: Use after free in WebView
Severity: high
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-24
Published