CVE-2026-13791
published 2026-06-30CVE-2026-13791: Insufficient validation of untrusted input in Downloads in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious…
PriorityP352high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.35%
28.1th percentile
Insufficient validation of untrusted input in Downloads in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 150.0.7871.46 | 150.0.7871.46 | |
| chrome | >= 150.0.7871.47 < 150.0.7871.47 | 150.0.7871.47 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2026-13791
vendor_chrome·2026-06-30·CVSS 8.1
CVE-2026-13791 [HIGH] Stable Channel Update for Desktop: CVE-2026-13791
Stable Channel Update for Desktop
CVE-2026-13791: Insufficient validation of untrusted input in Downloads. Reported by Ron Masas (Imperva) on 2026-04-17 [$4000][ 496012368 ] High CVE-2026-13792: Use after free in Touchbar
Reported by Weipeng Jiang (@Krace) of VRI on 2026-03-25 [$3000][ 510829679 ] High CVE-2026-13793: Insufficient policy enforcement in SVG
Severity: high
Red Hat
chromium-browser: Insufficient validation of untrusted input in Downloads
vendor_redhat·2026-06-30·CVSS 8.1
CVE-2026-13791 [HIGH] CWE-349 chromium-browser: Insufficient validation of untrusted input in Downloads
chromium-browser: Insufficient validation of untrusted input in Downloads
Insufficient validation of untrusted input in Downloads in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)
An insufficient validation of untrusted input flaw was found in the Downloads component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=503850012
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Chrome
Stable Channel Update for Desktop: CVE-2026-13789
vendor_chrome·2026-06-30
CVE-2026-13789 [HIGH] Stable Channel Update for Desktop: CVE-2026-13789
Stable Channel Update for Desktop
CVE-2026-13789: Use after free in GPU. Reported by 86ac1f1587b71893ed2ad792cd7dde32 on 2026-03-18 [$10000][ 457771782 ] High CVE-2026-13790: Side-channel information leakage in Scroll
Reported by Vsevolod Kokorin (Slonser) of Solidlab and Jorian Woltjer on 2025-11-04 [$10000][ 503850012 ] High CVE-2026-13791: Insufficient validation of untrusted input in Downloads
Severity: high
VulDB
Google Chrome up to 149.0.7827.201 Downloads input validation (ID 503850 / Nessus ID 325118)
vuldb·2026-07-07·CVSS 8.1
CVE-2026-13791 [HIGH] Google Chrome up to 149.0.7827.201 Downloads input validation (ID 503850 / Nessus ID 325118)
A vulnerability was found in Google Chrome. It has been rated as critical. Affected by this issue is some unknown functionality of the component Downloads. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2026-13791. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
GHSA
Insufficient validation of untrusted input in Downloads in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via
ghsa_unreviewed·2026-07-01
CVE-2026-13791 [HIGH] CWE-20 Insufficient validation of untrusted input in Downloads in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via
Insufficient validation of untrusted input in Downloads in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)
No detection rules found.
No public exploits indexed.
2026-06-30
Published