Description
Out of bounds read in Layout in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An out-of-bounds read flaw in the Layout component of Google Chrome before version 150.0.7871.47 allows a remote attacker to craft an HTML page that can read arbitrary data from the browser process memory. The vulnerability is a memory safety issue (CWE‑125) that can expose sensitive information stored in memory, such as user data or session information, by accessing data beyond the bounds of allocated buffers.

Affected Systems

All desktop installations of Google Chrome built on the Chromium engine whose version is older than 150.0.7871.47 are affected. No specific operating systems or builds were excluded in the advisory.

Risk and Exploitability

The CVSS score of 6.5 reflects medium severity. The EPSS score of < 1 % indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the delivery of a crafted HTML page via a malicious website or phishing email, which a victim would load in the browser. No public exploits have been reported, and the issue is considered to be purely informational if it is successfully triggered.

Generated by OpenCVE AI on July 17, 2026 at 14:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later.
  • Configure Chrome to automatically receive security updates through the default update channel.
  • Deploy additional content security controls, such as Site Isolation and a reputable browser extension that blocks malicious or suspicious HTML content.

Generated by OpenCVE AI on July 17, 2026 at 14:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Out-of-bounds Read in Chrome Layout Allows Remote Information Disclosure

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Chrome Layout Out-of-Bounds Read Exposes Process Memory

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Chrome Layout Out-of-Bounds Read Exposes Process Memory

Sat, 11 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Chrome Out-of-Bounds Read in Layout Component

Thu, 09 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Chrome Out-of-Bounds Read in Layout Component

Wed, 08 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome Layout Enables Remote Information Disclosure

Tue, 07 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome Layout Enables Remote Information Disclosure

Mon, 06 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Chrome Out-of-Bounds Read Allows Remote Information Disclosure

Mon, 06 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Chrome Out-of-Bounds Read Allows Remote Information Disclosure

Sun, 05 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via Out-of-Bounds Read in Chrome Layout

Sun, 05 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via Out-of-Bounds Read in Chrome Layout

Sat, 04 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Out of Bounds Read in Chrome Layout Enables Remote Information Disclosure

Fri, 03 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Out of Bounds Read in Chrome Layout Enables Remote Information Disclosure

Fri, 03 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome Layout Enables Remote Information Disclosure

Fri, 03 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome Layout Enables Remote Information Disclosure

Thu, 02 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Google Chrome Out-of-Bounds Read Allows Remote Information Disclosure

Thu, 02 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Google Chrome Out-of-Bounds Read Allows Remote Information Disclosure

Wed, 01 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome Layout Component Allows Remote Memory Disclosure
Weaknesses CWE-20

Wed, 01 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-125
CWE-787
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Chrome Layout Component Allows Remote Memory Disclosure
Weaknesses CWE-20

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Out of bounds read in Layout in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T01:18:10.523Z

Reserved: 2026-06-29T23:03:39.079Z

Link: CVE-2026-13873

cve-icon Vulnrichment

Updated: 2026-07-01T01:05:59.323Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T14:45:06Z

Weaknesses