Description
Use after free in HTML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use‑after‑free bug in the HTML parsing engine of Google Chrome before version 150.0.7871.47 allows a crafted HTML document to corrupt memory inside the browser’s sandbox. The flaw, classified as CWE‑416, can be leveraged by a remote attacker to execute arbitrary code within the sandboxed environment.

Affected Systems

The vulnerability affects all Google Chrome installations running any stable‑channel build earlier than 150.0.7871.47 on desktop platforms. No other vendors or products have been reported to be impacted by this issue.

Risk and Exploitability

The CVSS score of 8.8 categorizes the flaw as high severity, indicating significant risk for capable adversaries. The EPSS score of less than 1% reflects a very low probability of exploitation in the wild, and the flaw is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is a malicious HTML page that a user opens or visits, which can trigger the memory corruption when the page is parsed. Exploitation requires user interaction with the malicious content and would allow the attacker to execute code within the sandbox.

Generated by OpenCVE AI on July 16, 2026 at 12:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to at least version 150.0.7871.47 to remove the use‑after‑free flaw
  • If an immediate upgrade is not possible, enable the browser’s automatic update feature so that the fix is applied as soon as it becomes available
  • As a temporary mitigation, deploy browser group policies that restrict discretionary browsing of local or untrusted HTML content, thereby reducing the likelihood that malicious pages are loaded by users

Generated by OpenCVE AI on July 16, 2026 at 12:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Thu, 16 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome’s HTML Parser Enables Remote Code Execution

Tue, 14 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome HTML Parsing Enables Remote Code Execution

Sun, 12 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome HTML Parsing Enables Remote Code Execution

Sat, 11 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Vulnerability in Chrome Enables Remote Code Execution

Thu, 09 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free Vulnerability in Chrome Enables Remote Code Execution

Thu, 09 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome HTML Parsing Allows Remote Code Execution

Wed, 08 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome HTML Parsing Allows Remote Code Execution

Tue, 07 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome HTML Parsing Enables Sandbox Code Execution

Mon, 06 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome HTML Parsing Enables Sandbox Code Execution

Mon, 06 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome HTML Parser Allows Remote Code Execution

Sun, 05 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Use After Free in Chrome HTML Parser Allows Remote Code Execution

Sun, 05 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome HTML Parsing Allows Remote Code Execution

Sat, 04 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome HTML Parsing Allows Remote Code Execution

Sat, 04 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome’s HTML Engine Allows Remote Code Execution

Fri, 03 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome’s HTML Engine Allows Remote Code Execution

Fri, 03 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome HTML Parsing Allows Remote Code Execution

Thu, 02 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in Chrome HTML Parsing Allows Remote Code Execution

Thu, 02 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome's HTML Engine Enables Remote Code Execution in Sandbox

Thu, 02 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Use-After-Free in Chrome's HTML Engine Enables Remote Code Execution in Sandbox

Wed, 01 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome HTML Parser Allows Remote Code Execution

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Use‑After‑Free in Chrome HTML Parser Allows Remote Code Execution

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in HTML Enables Arbitrary Code Execution in Chrome Sandbox

Wed, 01 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Use‑after‑free in HTML Enables Arbitrary Code Execution in Chrome Sandbox

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Use after free in HTML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:57:05.465Z

Reserved: 2026-06-29T23:03:45.765Z

Link: CVE-2026-13899

cve-icon Vulnrichment

Updated: 2026-07-01T14:03:32.537Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-16T12:30:03Z

Weaknesses