Description
Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-06-30
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Google Chrome allows a remote attacker who has compromised the renderer process to supply a specially crafted HTML page that can escape the browser sandbox. The weakness is categorized as type confusion (CWE-843).

Affected Systems

Google Chrome browsers on all platforms that use the Dawn rendering engine and are running versions prior to 150.0.7871.47 are affected by this type‑confusion flaw. No other version granularity is currently known.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.6, denoting critical severity. The EPSS score is less than 1%, indicating a very low probability of exploitation. The flaw is not listed in CISA KEV. Based on the description, it is inferred that the attacker must control the renderer process, most likely through a malicious HTML page served over the network. Exploitation succeeds if the attacker can manipulate the type system within the Dawn engine to escape the browser sandbox.

Generated by OpenCVE AI on July 21, 2026 at 17:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 150.0.7871.47 or newer to apply the authoritative fix for the type‑confusion bug.
  • If upgrades are delayed, isolate the browser in a virtual machine or container with strict network restrictions to limit potential escape paths.
  • Check Chrome’s update settings to ensure it automatically updates to the latest security releases.

Generated by OpenCVE AI on July 21, 2026 at 17:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Tue, 21 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Title Type Confusion in Dawn Enables Sandbox Escape

Fri, 17 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Type Confusion in Dawn Enables Sandbox Escape

Thu, 16 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Type Confusion in Chrome Dawn Engine Enables Sandbox Escape

Tue, 14 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Type Confusion in Chrome Dawn Engine Enables Sandbox Escape

Mon, 13 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Dawn Rendering Engine Type Confusion Enables Remote Sandbox Escape in Chrome

Sat, 11 Jul 2026 17:45:00 +0000

Type Values Removed Values Added
Title Dawn Rendering Engine Type Confusion Enables Remote Sandbox Escape in Chrome

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Type Confusion in Chrome Dawn Engine Enabling Sandbox Escape

Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Type Confusion in Chrome Dawn Engine Enabling Sandbox Escape

Wed, 08 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Type Confusion in Chrome Dawn Engine Enables Sandbox Escape

Tue, 07 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Type Confusion in Chrome Dawn Engine Enables Sandbox Escape

Mon, 06 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Type Confusion in Chrome Dawn Engine Enables Sandbox Escape

Mon, 06 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Type Confusion in Chrome Dawn Engine Enables Sandbox Escape

Sun, 05 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Type Confusion Vulnerability Enables Chrome Sandbox Escape with Malicious HTML

Sun, 05 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Type Confusion Vulnerability Enables Chrome Sandbox Escape with Malicious HTML

Sun, 05 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Type Confusion in Chrome Dawn Allows Sandbox Escape

Sat, 04 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Type Confusion in Chrome Dawn Allows Sandbox Escape

Sat, 04 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Type Confusion in Chrome Dawn Engine Enables Sandbox Escape

Fri, 03 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Type Confusion in Chrome Dawn Engine Enables Sandbox Escape

Fri, 03 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Type Confusion in Chrome Dawn Engine Enables Sandbox Escape

Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Type Confusion in Chrome Dawn Engine Enables Sandbox Escape

Thu, 02 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Type Confusion in Chrome Dawn Engine Allows Sandbox Escape

Wed, 01 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Type Confusion in Chrome Dawn Engine Allows Sandbox Escape

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Chrome Dawn Type Confusion Leading to Sandbox Escape
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Chrome Dawn Type Confusion Leading to Sandbox Escape

Wed, 01 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Remote Sandbox Escape via Type Confusion in Chrome Dawn Rendering Engine

Wed, 01 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Remote Sandbox Escape via Type Confusion in Chrome Dawn Rendering Engine

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Weaknesses CWE-843
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:57:30.274Z

Reserved: 2026-06-29T23:03:14.295Z

Link: CVE-2026-13776

cve-icon Vulnrichment

Updated: 2026-07-01T17:17:34.829Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T17:45:02Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')