CVE-2026-13830
published 2026-06-30CVE-2026-13830: Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network…
PriorityP352high8.8CVSS 3.1
AVAACLPRNUINSUCHIHAH
EPSS
0.23%
13.5th percentile
Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 150.0.7871.46 | 150.0.7871.46 | |
| chrome | >= 150.0.7871.47 < 150.0.7871.47 | 150.0.7871.47 | |
| chrome_desktop | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 149.0.7827.201 on Linux Chromoting use after free (ID 513727)
vuldb·2026-07-05·CVSS 8.8
CVE-2026-13830 [HIGH] Google Chrome up to 149.0.7827.201 on Linux Chromoting use after free (ID 513727)
A vulnerability, which was classified as critical, was found in Google Chrome on Linux. Affected by this vulnerability is an unknown functionality of the component Chromoting. Executing a manipulation can lead to use after free.
The identification of this vulnerability is CVE-2026-13830. The attack may be launched remotely. There is no exploit available.
You should upgrade the affected component.
GHSA
Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic.
ghsa_unreviewed·2026-07-01
CVE-2026-13830 [HIGH] CWE-416 Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic.
Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)
Chrome
Stable Channel Update for Desktop: CVE-2026-13828
vendor_chrome·2026-06-30·CVSS 6.5
CVE-2026-13828 [HIGH] Stable Channel Update for Desktop: CVE-2026-13828
Stable Channel Update for Desktop
CVE-2026-13828: Inappropriate implementation in Enterprise. Reported by Google on 2026-05-15 [N/A][ 513490996 ] High CVE-2026-13829: Insufficient validation of untrusted input in Settings
Reported by Google on 2026-05-15 [N/A][ 513727494 ] High CVE-2026-13830: Use after free in Chromoting
Severity: high
Chrome
Stable Channel Update for Desktop: CVE-2026-13829
vendor_chrome·2026-06-30
CVE-2026-13829 [HIGH] Stable Channel Update for Desktop: CVE-2026-13829
Stable Channel Update for Desktop
CVE-2026-13829: Insufficient validation of untrusted input in Settings. Reported by Google on 2026-05-15 [N/A][ 513727494 ] High CVE-2026-13830: Use after free in Chromoting
Reported by Google on 2026-05-16 [N/A][ 513781328 ] High CVE-2026-13831: Use after free in GPU
Severity: high
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-30
Published