Description
Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from a lack of input validation during extension rendering in Google Chrome. A remote attacker who has first compromised the renderer process can present a crafted HTML page that triggers privileged operations, allowing the attacker to elevate privileges within the browser context. Classified as CWE-20, this weakness permits the execution of privileged browser commands, potentially compromising user data or system integrity. With a CVSS base score of 7.5, the flaw represents a medium-level risk for privilege escalation in the renderer process.

Affected Systems

All installations of Google Chrome prior to build 150.0.7871.47, including the stable channel, are vulnerable. The flaw resides in the extensions renderer component; users running a vulnerable build with an extension that processes untrusted input are at risk until the browser is updated.

Risk and Exploitability

Exploitation requires that the attacker first gain control of the renderer process, a non-trivial prerequisite that limits widespread attacks. The EPSS score of <1% and absence from CISA's KEV catalog indicate that documented exploitation is currently unknown. The CVSS score of 7.5 implies that, if exploited, the vulnerability could lead to privilege escalation within the browser but does not directly affect other system components unless the attacker escalates further.

Generated by OpenCVE AI on July 31, 2026 at 16:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later
  • Disable or remove any extensions that process untrusted input or are not essential
  • Ensure the Chrome sandbox is enabled and correctly configured to limit renderer privileges

Generated by OpenCVE AI on July 31, 2026 at 16:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 31 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Chrome Extension Renderer Input Validation Vulnerability Allows Privilege Escalation

Mon, 27 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Unvalidated Extension Input in Chrome Allows Privilege Escalation

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Title Unvalidated Extension Input in Chrome Allows Privilege Escalation

Wed, 22 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Chrome Extension Renderer Privilege Escalation via Unvalidated Input

Fri, 17 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Chrome Extension Renderer Privilege Escalation via Unvalidated Input

Thu, 16 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Extensions Enables Renderer-Based Privilege Escalation

Tue, 14 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Extensions Enables Renderer-Based Privilege Escalation

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Unvalidated Input in Chrome Extensions Renderer

Sun, 12 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Unvalidated Input in Chrome Extensions Renderer

Sat, 11 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Chrome Extension Input Validation Weakness Enabling Renderer Privilege Escalation

Thu, 09 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Chrome Extension Input Validation Weakness Enabling Renderer Privilege Escalation

Wed, 08 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome Extensions Enables Privilege Escalation

Tue, 07 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome Extensions Enables Privilege Escalation

Mon, 06 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Untrusted Input in Chrome Extensions

Mon, 06 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Untrusted Input in Chrome Extensions

Sun, 05 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Extensions Enables Privilege Escalation

Sun, 05 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Extensions Enables Privilege Escalation

Sat, 04 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome Extensions Enables Remote Privilege Escalation

Sat, 04 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome Extensions Enables Remote Privilege Escalation

Fri, 03 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome Extensions Enables Privilege Escalation

Thu, 02 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome Extensions Enables Privilege Escalation

Thu, 02 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation through Unvalidated Input in Chrome Extensions

Wed, 01 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation through Unvalidated Input in Chrome Extensions

Wed, 01 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Untrusted Input in Chrome Extensions Enables Privilege Escalation

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Untrusted Input in Chrome Extensions Enables Privilege Escalation

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:55:21.112Z

Reserved: 2026-06-29T23:03:43.497Z

Link: CVE-2026-13891

cve-icon Vulnrichment

Updated: 2026-07-01T12:58:14.335Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-30T23:17:03.333

Modified: 2026-07-02T05:16:35.483

Link: CVE-2026-13891

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T16:30:17Z

Weaknesses
  • CWE-20

    Improper Input Validation