Description
Use after free in IME in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a use‑after‑free bug in Google Chrome’s Input Method Editor that allows a malicious web page to trigger arbitrary code execution inside Chrome’s sandbox. Exploitation relies on rendering a crafted HTML document and exploits memory corruption to read or write data during the parsing of that page. The vulnerability is rated high severity by Chromium due to its ability to elevate privileges within the browser process.

Affected Systems

All Google Chrome installations earlier than version 150.0.7871.47, regardless of operating system, are vulnerable until the user updates to the patched release.

Risk and Exploitability

With a CVSS score of 8.8, the issue is considered high severity, while an EPSS score of less than 1% and absence from CISA’s KEV catalog suggest a low likelihood of current exploitation. The attack vector is a crafted web page that automatically loads in Chrome, allowing an attacker to run code with the same privileges as the user within the browser’s sandbox.

Generated by OpenCVE AI on August 2, 2026 at 01:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later, which eliminates the use‑after‑free bug.
  • Enable Chrome’s automatic update mechanism so that any future patches for memory safety will be installed without manual intervention.
  • Restrict or disable the Input Method Editor for sites or extensions that do not require it to reduce the attack surface.

Generated by OpenCVE AI on August 2, 2026 at 01:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Sun, 02 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome IME Enables Remote Code Execution

Wed, 29 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Chrome Use-After-Free in IME Allows Remote Code Execution

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Chrome Use-After-Free in IME Allows Remote Code Execution

Wed, 22 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome IME Allows Remote Code Execution via Crafted Web Page

Fri, 17 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome IME Allows Remote Code Execution via Crafted Web Page

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome IME Enables Remote Code Execution via Crafted Web Page

Tue, 14 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome IME Enables Remote Code Execution via Crafted Web Page

Sun, 12 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome IME Enables Remote Code Execution via Crafted HTML

Sat, 11 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome IME Enables Remote Code Execution via Crafted HTML

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome IME Enables Remote Code Execution

Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome IME Enables Remote Code Execution

Tue, 07 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome IME Allows Remote Code Execution

Mon, 06 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome IME Allows Remote Code Execution

Sun, 05 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Chrome Use-After-Free in IME Enables Remote Code Execution from Crafted Web Page

Sun, 05 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Chrome Use-After-Free in IME Enables Remote Code Execution from Crafted Web Page

Sat, 04 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome IME Allows Remote Code Execution via Crafted Page

Fri, 03 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome IME Allows Remote Code Execution via Crafted Page

Fri, 03 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome IME allows Remote Code Execution

Thu, 02 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome IME allows Remote Code Execution

Thu, 02 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome IME Allows Remote Code Execution

Thu, 02 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome IME Allows Remote Code Execution

Thu, 02 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome IME Enables Remote Code Execution via Crafted HTML

Wed, 01 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome IME Enables Remote Code Execution via Crafted HTML

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome IME Enables Remote Code Execution via Crafted Page

Wed, 01 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome IME Enables Remote Code Execution via Crafted Page

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Use after free in IME in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:55:46.118Z

Reserved: 2026-06-29T23:03:23.544Z

Link: CVE-2026-13811

cve-icon Vulnrichment

Updated: 2026-07-01T13:35:56.638Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T01:15:13Z

Weaknesses