CVE-2026-13281
published 2026-06-25CVE-2026-13281: Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a…
PriorityP345high8.3CVSS 3.1
AVNACHPRNUIRSCCHIHAH
EPSS
0.18%
7.5th percentile
Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 149.0.7827.200 | 149.0.7827.200 | |
| chrome | >= 149.0.7827.201 < 149.0.7827.201 | 149.0.7827.201 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.18.3HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
vendor_redhat8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2026-13281
vendor_chrome·2026-06-25
CVE-2026-13281 [HIGH] Stable Channel Update for Desktop: CVE-2026-13281
Stable Channel Update for Desktop
CVE-2026-13281: Integer overflow in Mojo. Reported by Google on 2026-05-14 [N/A][ 517522620 ] High CVE-2026-13282: Use after free in Payments
Reported by Google on 2026-05-28 [N/A][ 522561151 ] High CVE-2026-13283: Use after free in AdFilter
Severity: high
Red Hat
chromium-browser: chromium-browser: Integer overflow in Mojo
vendor_redhat·2026-06-25·CVSS 8.3
CVE-2026-13281 [HIGH] CWE-190 chromium-browser: chromium-browser: Integer overflow in Mojo
chromium-browser: chromium-browser: Integer overflow in Mojo
Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
An integer overflow flaw was found in the Mojo component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=513138301
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
GHSA
Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file.
ghsa_unreviewed·2026-06-26
CVE-2026-13281 [HIGH] CWE-472 Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file.
Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
VulDB
Google Chrome up to 149.0.7827.197 Mojo external control of assumed-immutable web parameter (ID 513138 / EUVD-2026-39583)
vuldb·2026-06-26
CVE-2026-13281 [CRITICAL] Google Chrome up to 149.0.7827.197 Mojo external control of assumed-immutable web parameter (ID 513138 / EUVD-2026-39583)
A vulnerability described as critical has been identified in Google Chrome. Impacted is an unknown function of the component Mojo. Such manipulation leads to external control of assumed-immutable web parameter.
This vulnerability is traded as CVE-2026-13281. The attack may be launched remotely. There is no exploit available.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-13281 chromium: chromium-browser: Integer overflow in Mojo [epel-all]
bugzilla·2026-06-29·CVSS 8.3
CVE-2026-13281 [HIGH] CVE-2026-13281 chromium: chromium-browser: Integer overflow in Mojo [epel-all]
CVE-2026-13281 chromium: chromium-browser: Integer overflow in Mojo [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Discussion:
Fixed in chromium-149.0.7827.200
Bugzilla
CVE-2026-13281 chromium: chromium-browser: Integer overflow in Mojo [fedora-all]
bugzilla·2026-06-29·CVSS 8.3
CVE-2026-13281 [HIGH] CVE-2026-13281 chromium: chromium-browser: Integer overflow in Mojo [fedora-all]
CVE-2026-13281 chromium: chromium-browser: Integer overflow in Mojo [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Discussion:
Fixed in chromium-149.0.7827.200
Bugzilla
CVE-2026-13281 chromium-browser: chromium-browser: Integer overflow in Mojo
bugzilla·2026-06-25·CVSS 8.3
CVE-2026-13281 [HIGH] CVE-2026-13281 chromium-browser: chromium-browser: Integer overflow in Mojo
CVE-2026-13281 chromium-browser: chromium-browser: Integer overflow in Mojo
Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)
Bugzilla
CVE-2025-13281 cri-tools: Portworx Half-Blind SSRF in kube-controller-manager [fedora-42]
bugzilla·2025-12-15·CVSS 5.8
CVE-2025-13281 [MEDIUM] CVE-2025-13281 cri-tools: Portworx Half-Blind SSRF in kube-controller-manager [fedora-42]
CVE-2025-13281 cri-tools: Portworx Half-Blind SSRF in kube-controller-manager [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bu
Bugzilla
CVE-2025-13281 kubernetes1.30: Portworx Half-Blind SSRF in kube-controller-manager [fedora-42]
bugzilla·2025-12-15·CVSS 5.8
CVE-2025-13281 [MEDIUM] CVE-2025-13281 kubernetes1.30: Portworx Half-Blind SSRF in kube-controller-manager [fedora-42]
CVE-2025-13281 kubernetes1.30: Portworx Half-Blind SSRF in kube-controller-manager [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close a
Bugzilla
CVE-2025-13281 kubernetes1.29: Portworx Half-Blind SSRF in kube-controller-manager [fedora-42]
bugzilla·2025-12-15·CVSS 5.8
CVE-2025-13281 [MEDIUM] CVE-2025-13281 kubernetes1.29: Portworx Half-Blind SSRF in kube-controller-manager [fedora-42]
CVE-2025-13281 kubernetes1.29: Portworx Half-Blind SSRF in kube-controller-manager [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close a
Bugzilla
CVE-2025-13281 cri-tools1.30: Portworx Half-Blind SSRF in kube-controller-manager [fedora-42]
bugzilla·2025-12-15·CVSS 5.8
CVE-2025-13281 [MEDIUM] CVE-2025-13281 cri-tools1.30: Portworx Half-Blind SSRF in kube-controller-manager [fedora-42]
CVE-2025-13281 cri-tools1.30: Portworx Half-Blind SSRF in kube-controller-manager [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close al
Bugzilla
CVE-2025-13281 cri-tools1.29: Portworx Half-Blind SSRF in kube-controller-manager [fedora-42]
bugzilla·2025-12-15·CVSS 5.8
CVE-2025-13281 [MEDIUM] CVE-2025-13281 cri-tools1.29: Portworx Half-Blind SSRF in kube-controller-manager [fedora-42]
CVE-2025-13281 cri-tools1.29: Portworx Half-Blind SSRF in kube-controller-manager [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close al
2026-06-25
Published