CVE-2026-16805
published 2026-07-23CVE-2026-16805: Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page…
PriorityP355high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.31%
23.8th percentile
Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 150.0.7871.186 | 150.0.7871.186 | |
| chrome | >= 150.0.7871.186 < 150.0.7871.186 | 150.0.7871.186 | |
| chrome_desktop | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
ghsa_unreviewed·2026-07-24
CVE-2026-16805 [HIGH] CWE-416 Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Use after free in Blink in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
VulDB
Google Chrome up to 150.0.7871.182 Blink use after free
vuldb·2026-07-24
CVE-2026-16805 [CRITICAL] Google Chrome up to 150.0.7871.182 Blink use after free
A vulnerability marked as critical has been reported in Google Chrome. Impacted is an unknown function of the component Blink. Performing a manipulation results in use after free.
This vulnerability is reported as CVE-2026-16805. The attack is possible to be carried out remotely. No exploit exists.
It is suggested to upgrade the affected component.
Chrome
Stable Channel Update for Desktop: CVE-2026-16807
vendor_chrome·2026-07-23
CVE-2026-16807 [HIGH] Stable Channel Update for Desktop: CVE-2026-16807
Stable Channel Update for Desktop
CVE-2026-16807: Out of bounds write in Codecs. Reported by Google on 2026-05-30 [N/A][ 522064153 ] High CVE-2026-16806: Use after free in WebMCP
Reported by Google on 2026-06-10 [N/A][ 523292588 ] High CVE-2026-16805: Use after free in Blink
Severity: high
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-23
Published