Description
Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free flaw exists in Chrome’s Bluetooth handling on macOS. A remote attacker who has already compromised the renderer process can trigger the defect by serving a crafted HTML page, causing the renderer to access freed memory and potentially escape its sandbox. The flaw is classified as CWE‑416, and Chromium rates it as medium severity.

Affected Systems

Google Chrome on macOS versions prior to 150.0.7871.47 with Bluetooth enabled is vulnerable. Any installation where Bluetooth is implemented within the browser is impacted until the product is upgraded to the patched release.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.6, indicating high severity. The EPSS score is less than 1%, suggesting a very low likelihood of exploitation at present. The flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to already have compromised the renderer process and trigger the use‑after‑free through a crafted HTML page, potentially leading to a sandbox escape.

Generated by OpenCVE AI on July 16, 2026 at 12:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest update for Google Chrome on macOS, version 150.0.7871.47 or later.
  • If an update cannot be applied immediately, disable Bluetooth in Chrome settings or block Bluetooth access via system preferences to eliminate the attack surface.
  • Remove or disable third‑party extensions that provide Bluetooth functionality to prevent them from aiding a compromised renderer.

Generated by OpenCVE AI on July 16, 2026 at 12:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Thu, 16 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome Bluetooth Allows Remote Sandbox Escape on macOS

Tue, 14 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome Bluetooth Allows Remote Sandbox Escape on macOS

Tue, 14 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Chrome Bluetooth Use-After-Free Enables Sandbox Escape on macOS

Mon, 13 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Chrome Bluetooth Use-After-Free Enables Sandbox Escape on macOS

Sun, 12 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Bluetooth Enables Sandbox Escape on macOS

Fri, 10 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Bluetooth Enables Sandbox Escape on macOS

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Bluetooth Enables Remote Sandbox Escape on macOS

Wed, 08 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Bluetooth Enables Remote Sandbox Escape on macOS

Tue, 07 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Bluetooth Enabling Sandbox Escape via Crafted HTML on macOS

Tue, 07 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Bluetooth Enabling Sandbox Escape via Crafted HTML on macOS

Mon, 06 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Bluetooth Allows Remote Sandbox Escape

Mon, 06 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Bluetooth Allows Remote Sandbox Escape

Sun, 05 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Bluetooth Enables Sandbox Escape on macOS

Sun, 05 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Bluetooth Enables Sandbox Escape on macOS

Sat, 04 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Bluetooth on macOS Leading to Potential Sandbox Escape

Sat, 04 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Bluetooth on macOS Leading to Potential Sandbox Escape

Fri, 03 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Chrome macOS Bluetooth Use-After-Free Enables Sandbox Escape

Fri, 03 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Chrome macOS Bluetooth Use-After-Free Enables Sandbox Escape

Thu, 02 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Remote Sandbox Escape via Bluetooth Use-After‑Free in Chrome

Thu, 02 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Remote Sandbox Escape via Bluetooth Use-After‑Free in Chrome

Wed, 01 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Bluetooth Allows Potential Sandbox Escape on macOS

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome Bluetooth Allows Potential Sandbox Escape on macOS

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Bluetooth on macOS

Wed, 01 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome Bluetooth on macOS

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T19:06:16.145Z

Reserved: 2026-06-29T23:03:40.328Z

Link: CVE-2026-13878

cve-icon Vulnrichment

Updated: 2026-07-01T14:56:42.324Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-16T12:45:05Z

Weaknesses