Description
Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a use‑after‑free bug in Chrome’s GPU component that allows an attacker who has already compromised the renderer process to escape the browser sandbox and execute arbitrary code on the host operating system. This vulnerability falls under CWE‑416 and carries the potential for total system compromise.

Affected Systems

Google Chrome browsers with versions earlier than 150.0.7871.47 are affected. Any system running a vulnerable Chrome build remains at risk until the patch is installed.

Risk and Exploitability

Chromium assigns a CVSS score of 9.6 and an EPSS probability of less than 1%. The vulnerability is not referenced in CISA’s KEV catalog. The likely attack vector is a crafted HTML page that could compromise the renderer, which typically requires an attacker to already have compromised the renderer process or deliver malicious content to the user. Given the high impact and the absence of alternative mitigations outside of patching, the threat to exposed systems remains significant.

Generated by OpenCVE AI on July 17, 2026 at 15:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to at least version 150.0.7871.47 or newer to contain the use‑after‑free bug.
  • Ensure Chrome runs under least‑privilege accounts and that OS‑level sandboxing or application whitelisting limits damage from a sandbox escape.
  • Educate and train users to recognize and avoid malicious web content that could deliver crafted HTML pages, as the vulnerability requires exploitation via the renderer process.

Generated by OpenCVE AI on July 17, 2026 at 15:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
History

Fri, 17 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome GPU Enables Sandbox Escape

Thu, 16 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome GPU Enables Sandbox Escape

Tue, 14 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Chrome GPU Use‑After‑Free Leading to Sandbox Escape

Mon, 13 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Chrome GPU Use‑After‑Free Leading to Sandbox Escape

Sun, 12 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome GPU Facilitates Sandbox Escape

Sat, 11 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome GPU Facilitates Sandbox Escape

Fri, 10 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome GPU Allows Sandbox Escape

Fri, 10 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome GPU Allows Sandbox Escape

Thu, 09 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome GPU Enables Sandbox Escape

Wed, 08 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome GPU Enables Sandbox Escape

Tue, 07 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Chrome GPU Use‑After‑Free Enables Sandbox Escape

Tue, 07 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Chrome GPU Use‑After‑Free Enables Sandbox Escape

Mon, 06 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free Vulnerability in Chrome GPU Allows Sandbox Escape

Sun, 05 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free Vulnerability in Chrome GPU Allows Sandbox Escape

Sun, 05 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome GPU Component Enables Sandbox Escape

Sat, 04 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome GPU Component Enables Sandbox Escape

Sat, 04 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome GPU Enables Sandbox Escape

Fri, 03 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome GPU Enables Sandbox Escape

Thu, 02 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title GPU Use-After-Free Allows Chrome Sandbox Escape

Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title GPU Use-After-Free Allows Chrome Sandbox Escape

Thu, 02 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Chrome GPU Use-After-Free Allows Sandbox Escape

Wed, 01 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Chrome GPU Use-After-Free Allows Sandbox Escape

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome GPU Allows Sandbox Escape

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome GPU Allows Sandbox Escape

Wed, 01 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome GPU Allows Sandbox Escape

Wed, 01 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome GPU Allows Sandbox Escape

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:57:17.989Z

Reserved: 2026-06-29T23:03:18.117Z

Link: CVE-2026-13789

cve-icon Vulnrichment

Updated: 2026-07-01T17:55:10.338Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T15:15:16Z

Weaknesses