CVE-2026-13805
published 2026-06-30CVE-2026-13805: Use after free in GFX in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium…
PriorityP353high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.35%
27.2th percentile
Use after free in GFX in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 150.0.7871.47 | 150.0.7871.47 | |
| chrome | >= 150.0.7871.47 < 150.0.7871.47 | 150.0.7871.47 | |
| chrome_desktop | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 149.0.7827.201 on macOS GFX use after free
vuldb·2026-07-04·CVSS 8.8
CVE-2026-13805 [HIGH] Google Chrome up to 149.0.7827.201 on macOS GFX use after free
A vulnerability labeled as critical has been found in Google Chrome on macOS. The impacted element is an unknown function of the component GFX. Executing a manipulation can lead to use after free.
This vulnerability is handled as CVE-2026-13805. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
GHSA
Use after free in GFX in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
ghsa_unreviewed·2026-07-01
CVE-2026-13805 [HIGH] CWE-416 Use after free in GFX in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page.
Use after free in GFX in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Chrome
Stable Channel Update for Desktop: CVE-2026-13805
vendor_chrome·2026-06-30·CVSS 8.8
CVE-2026-13805 [HIGH] Stable Channel Update for Desktop: CVE-2026-13805
Stable Channel Update for Desktop
CVE-2026-13805: Use after free in GFX. Reported by Google on 2026-04-13 [N/A][ 503054174 ] High CVE-2026-14390: Use after free in ANGLE
Reported by Google on 2026-04-15 [N/A][ 503333798 ] High CVE-2026-13806: Insufficient validation of untrusted input in Accessibility
Severity: high
Chrome
Stable Channel Update for Desktop: CVE-2026-13803
vendor_chrome·2026-06-30
CVE-2026-13803 [HIGH] Stable Channel Update for Desktop: CVE-2026-13803
Stable Channel Update for Desktop
CVE-2026-13803: Type Confusion in Chrome Tabs. Reported by Google on 2026-04-11 [N/A][ 501873032 ] High CVE-2026-13804: Use after free in Chromecast
Reported by Google on 2026-04-12 [N/A][ 502282040 ] High CVE-2026-13805: Use after free in GFX
Severity: high
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-30
Published