cbcvebase.
CVE-2026-13782
published 2026-06-30

CVE-2026-13782: Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a…

PriorityP263critical10CVSS 3.1
AVNACLPRNUINSCCHIHAH
EPSS
0.29%
21.1th percentile
Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Affected

3 ranges
VendorProductVersion rangeFixed in
googlechrome< 150.0.7871.46150.0.7871.46
googlechrome>= 150.0.7871.47 < 150.0.7871.47150.0.7871.47
googlechrome_desktop

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2026-13782 is a Use-After-Free in the Chrome Browser process (not renderer), exploitable via a crafted HTML page by an attacker who has already compromised the renderer process — detection should focus on renderer-to-browser process privilege escalation or unexpected Browser process memory corruption crashes.
  • Any Chrome installation running a version prior to 150.0.7871.47 is vulnerable; inventory and alert on outdated Chrome versions below this threshold.
  • ·Exploitation requires a prior renderer compromise as a prerequisite; this is a sandbox escape primitive, not a standalone initial-access vector.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.