Description
Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Google Chrome Enterprise before version 150.0.7871.47 allows a remote attacker to read potentially sensitive data from the browser's process memory by loading a specially crafted HTML page. This leads to information disclosure and is identified as an access-control weakness (CWE-284). The result is the exposure of confidential data that is processed by Chrome, earning a high‑severity label from the Chromium security team.

Affected Systems

All installations of Google Chrome Enterprise running any Chrome version older than 150.0.7871.47 are affected. The issue does not apply to later releases that incorporate the fix.

Risk and Exploitability

The vulnerability can be triggered by a malicious or compromised web page that, giving a remote attacker the ability to read process memory. The 6.5 suggests a moderate‑to‑high risk of information disclosure, while the EPSS score of < 1% indicates a very low but non‑zero likelihood of exploitation. The flaw is currently not listed in the CISA KEV catalog.

Generated by OpenCVE AI on July 17, 2026 at 14:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all Chrome Enterprise installations to version 150.0.7871.47 or later.
  • Configure Chrome Enterprise policies to automatically deploy the latest security updates.
  • Monitor web content for malicious or suspicious HTML and block or alert on unexpected scripts.

Generated by OpenCVE AI on July 17, 2026 at 14:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Thu, 16 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Chrome Enterprise Process Memory Disclosure via Crafted HTML Page

Tue, 14 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Chrome Enterprise Process Memory Disclosure via Crafted HTML Page

Sun, 12 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via Process Memory Read in Chrome Enterprise

Sat, 11 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via Process Memory Read in Chrome Enterprise

Fri, 10 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Chrome Enterprise Vulnerability Enables Memory Disclosure via Crafted HTML

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Chrome Enterprise Vulnerability Enables Memory Disclosure via Crafted HTML

Wed, 08 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Chrome Enterprise Process Memory Disclosure via Crafted HTML

Tue, 07 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Chrome Enterprise Process Memory Disclosure via Crafted HTML

Mon, 06 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Process Memory Leak Leads to Remote Information Disclosure in Chrome Enterprise

Mon, 06 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Process Memory Leak Leads to Remote Information Disclosure in Chrome Enterprise

Sun, 05 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Chrome Enterprise Process Memory Disclosure via Crafted HTML Page

Sat, 04 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Chrome Enterprise Process Memory Disclosure via Crafted HTML Page

Fri, 03 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Chrome Enterprise Remote Memory Disclosure via Crafted HTML Page

Fri, 03 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Chrome Enterprise Remote Memory Disclosure via Crafted HTML Page

Thu, 02 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Chrome Enterprise Memory Disclosure Vulnerability

Thu, 02 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Chrome Enterprise Memory Disclosure Vulnerability

Wed, 01 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure Vulnerability in Google Chrome Enterprise Prior to 150.0.7871.47

Wed, 01 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure Vulnerability in Google Chrome Enterprise Prior to 150.0.7871.47

Wed, 01 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Chrome Enterprise Memory Disclosure via Crafted HTML Page
Weaknesses CWE-200

Wed, 01 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Chrome Enterprise Memory Disclosure via Crafted HTML Page
Weaknesses CWE-200

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T01:28:50.188Z

Reserved: 2026-06-29T23:03:27.710Z

Link: CVE-2026-13828

cve-icon Vulnrichment

Updated: 2026-07-01T01:28:41.837Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T15:00:10Z

Weaknesses