Description
Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw in the Ozone backend of Google Chrome on Linux allows a remote attacker to reference freed memory by serving a specially crafted HTML page that requires the user to perform specific UI gestures. Successful exploitation results in arbitrary code execution with the privileges of the browser process. The weakness matches CWE‑416 and is rated as high severity by Chromium’s own assessment.

Affected Systems

The vulnerability affects all Google Chrome deployments on Linux running any version prior to 150.0.7871.47.

Risk and Exploitability

The CVSS score of 7.5 indicates a high potential impact. However, the EPSS score falls below 1%, and the flaw is not listed in CISA’s KEV catalog, suggesting an overall low probability of large‑scale exploitation. Exploitation requires the victim to open a malicious HTML document and perform specific UI gestures, so social engineering is a prerequisite. If the conditions are satisfied, the attacker can gain complete control of the browser and potentially the host system.

Generated by OpenCVE AI on July 17, 2026 at 14:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later.
  • Enable and enforce automatic updates to ensure timely application of security patches.
  • Restrict access to untrusted web content or enforce content‑security policies to reduce the need for UI gestures that may trigger the flaw.
  • Monitor Chrome process activity for anomalous code execution patterns as an additional detection measure.

Generated by OpenCVE AI on July 17, 2026 at 14:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Ozone Backend Enables Remote Code Execution on Linux

Mon, 13 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Use-after-free in Chrome Ozone Backend on Linux allows Remote Code Execution

Sun, 12 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Use-after-free in Chrome Ozone Backend on Linux allows Remote Code Execution

Sat, 11 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome's Ozone on Linux Enables Remote Code Execution via Crafted HTML

Fri, 10 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome's Ozone on Linux Enables Remote Code Execution via Crafted HTML

Thu, 09 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Ozone on Linux Enabling Remote Code Execution

Wed, 08 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Ozone on Linux Enabling Remote Code Execution

Tue, 07 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Ozone Allows Remote Code Execution via Crafted Page

Tue, 07 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Ozone Allows Remote Code Execution via Crafted Page

Mon, 06 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome's Ozone Rendering Engine Allows Remote Code Execution on Linux

Sun, 05 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome's Ozone Rendering Engine Allows Remote Code Execution on Linux

Sun, 05 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Ozone on Linux Enables Remote Code Execution via Crafted Web Page

Sun, 05 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Ozone on Linux Enables Remote Code Execution via Crafted Web Page

Sat, 04 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Ozone Leading to Remote Code Execution on Linux

Sat, 04 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Ozone Leading to Remote Code Execution on Linux

Fri, 03 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Linux Ozone Enables Remote Code Execution from Web Page

Fri, 03 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Linux Ozone Enables Remote Code Execution from Web Page

Thu, 02 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Execution via Crafted HTML Page

Thu, 02 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Execution via Crafted HTML Page

Wed, 01 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Chrome Linux Use‑After‑Free in Ozone Enables Remote Code Execution via Malicious HTML

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Chrome Linux Use‑After‑Free in Ozone Enables Remote Code Execution via Malicious HTML

Wed, 01 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:55:31.858Z

Reserved: 2026-06-29T23:03:34.634Z

Link: CVE-2026-13855

cve-icon Vulnrichment

Updated: 2026-07-01T13:20:53.056Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T15:00:10Z

Weaknesses