CVE-2026-16806
published 2026-07-23CVE-2026-16806: Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page…
PriorityP355high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.40%
32.5th percentile
Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 150.0.7871.186 | 150.0.7871.186 | |
| chrome | >= 150.0.7871.186 < 150.0.7871.186 | 150.0.7871.186 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP
vendor_redhat·2026-07-23·CVSS 8.8
CVE-2026-16806 [HIGH] chromium-browser: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP
chromium-browser: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP
A flaw was found in WebMCP, a component of Google Chrome. This vulnerability, known as a use-after-free, allows a remote attacker to execute arbitrary code within the browser's security sandbox. This can occur when a user visits a specially crafted HTML page, potentially leading to unauthorized control over the affected system.
Statement: This vulnerability is rated Important as it allows a remote attacker to achieve arbitrary code execution within the Chromium browser's sandbox. The flaw, a use-after-free in the WebMCP component, is triggered when a user navigates to a specially crafted HTML page, posing a significant risk of unauthorized system control.
Chrome
Stable Channel Update for Desktop: CVE-2026-16807
vendor_chrome·2026-07-23
CVE-2026-16807 [HIGH] Stable Channel Update for Desktop: CVE-2026-16807
Stable Channel Update for Desktop
CVE-2026-16807: Out of bounds write in Codecs. Reported by Google on 2026-05-30 [N/A][ 522064153 ] High CVE-2026-16806: Use after free in WebMCP
Reported by Google on 2026-06-10 [N/A][ 523292588 ] High CVE-2026-16805: Use after free in Blink
Severity: high
GHSA
Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
ghsa_unreviewed·2026-07-24
CVE-2026-16806 [HIGH] CWE-416 Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
VulDB
Google Chrome up to 150.0.7871.182 WebMCP use after free
vuldb·2026-07-24
CVE-2026-16806 [CRITICAL] Google Chrome up to 150.0.7871.182 WebMCP use after free
A vulnerability described as critical has been identified in Google Chrome. The affected element is an unknown function of the component WebMCP. Executing a manipulation can lead to use after free.
This vulnerability appears as CVE-2026-16806. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-16806 chromium: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP [fedora-all]
bugzilla·2026-07-24·CVSS 8.8
CVE-2026-16806 [HIGH] CVE-2026-16806 chromium: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP [fedora-all]
CVE-2026-16806 chromium: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Bugzilla
CVE-2026-16806 chromium: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP [epel-all]
bugzilla·2026-07-24·CVSS 8.8
CVE-2026-16806 [HIGH] CVE-2026-16806 chromium: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP [epel-all]
CVE-2026-16806 chromium: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Bugzilla
CVE-2026-16806 chromium-browser: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP
bugzilla·2026-07-23·CVSS 8.8
CVE-2026-16806 [HIGH] CVE-2026-16806 chromium-browser: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP
CVE-2026-16806 chromium-browser: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP
Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
2026-07-23
Published