Description
Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Google Chrome is a heap corruption vulnerability caused by an inappropriate XML parsing implementation in versions prior to 150.0.7871.47. When the browser parses a specially crafted HTML page, memory on the heap can be corrupted, potentially allowing a remote attacker to affect the stability or behavior of the browser. The official description indicates a high severity rating but does not state that arbitrary code execution is guaranteed, so the worst‑case impact is limited to corruption of browser state.

Affected Systems

Chrome versions older than 150.0.7871.47 are affected. The vulnerability originates in the browser’s XML parser and is triggered when the browser loads an HTML page that contains a maliciously constructed XML payload, typically served from a compromised or malicious website.

Risk and Exploitability

With a CVSS score of 8.8 the vulnerability is highly severe, yet the extremely low EPSS score (<1%) indicates that exploitation is unlikely under normal conditions. The vulnerability is not listed in CISA’s KEV catalog, and no public exploits have been reported. The most plausible attack scenario involves a malicious or compromised site delivering the crafted HTML page to a victim’s browser, but the exact impact of a successful exploit remains uncertain due to the lack of confirmed exploitation evidence.

Generated by OpenCVE AI on July 16, 2026 at 00:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later to eliminate the heap corruption flaw.
  • Enable automatic updates for Chrome so that future security patches the upgrade is performed, limit Chrome’s exposure to untrusted sources by blocking suspicious websites or applying network filtering to restrict access from potentially malicious domains.
  • Configure Chrome’s enterprise policy to disable legacy XML parsing when loading untrusted content.

Generated by OpenCVE AI on July 16, 2026 at 00:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Thu, 16 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Improper XML Parsing Enables Heap Corruption in Google Chrome

Mon, 13 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Heap Corruption Vulnerability in Chrome XML Parser

Sun, 12 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Heap Corruption Vulnerability in Chrome XML Parser

Sat, 11 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Inappropriate XML Parsing in Chrome

Fri, 10 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Inappropriate XML Parsing in Chrome

Thu, 09 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Heap Corruption via XML Parsing in Google Chrome Prior to 150.0.7871.47

Wed, 08 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Heap Corruption via XML Parsing in Google Chrome Prior to 150.0.7871.47

Tue, 07 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Crafted HTML in Google Chrome

Mon, 06 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Crafted HTML in Google Chrome

Sun, 05 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Heap Corruption via XML Parser in Google Chrome

Sun, 05 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Heap Corruption via XML Parser in Google Chrome

Sat, 04 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title XML Heap Corruption via Crafted HTML in Google Chrome

Fri, 03 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title XML Heap Corruption via Crafted HTML in Google Chrome

Thu, 02 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Heap Corruption via XML Parsing in Google Chrome

Thu, 02 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Heap Corruption via XML Parsing in Google Chrome

Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Malformed XML in Chrome

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Malformed XML in Chrome
Weaknesses CWE-122

Wed, 01 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Inadequate XML Handling in Chrome
Weaknesses CWE-122

Wed, 01 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Title Heap Corruption via Inadequate XML Handling in Chrome
Weaknesses CWE-122

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:56:24.840Z

Reserved: 2026-06-29T23:03:29.523Z

Link: CVE-2026-13835

cve-icon Vulnrichment

Updated: 2026-07-01T14:55:20.856Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-16T00:30:16Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow