Description
Inappropriate implementation in Downloads in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The CVE describes an inappropriate implementation in Chrome’s download handling on Windows that allows a remote attacker to execute arbitrary code by convincing a user to perform specific UI gestures after visiting a crafted HTML page. An input validation issue (CWE‑20) is leveraged, and the flaw depends on the user granting download consent. Chromium rates this as medium severity with a CVSS score of 7.5, indicating a high‑impact vulnerability.

Affected Systems

Google Chrome versions on Windows released prior to 150.0.7871.47 are affected. The fix is included in the stable channel update 150.0.7871.47 and later releases.

Risk and Exploitability

The EPSS score is below 1% and the flaw is not listed in CISA KEV, but the CVSS rating of 7.5 signals that an exploit can lead to full system compromise. Attackers need the victim to interact with a malicious page and perform a minimal UI gesture; once triggered, the flaw allows arbitrary code execution with the browser’s privileges. The low EPSS suggests a limited exploitation risk at present, but the high impact warrants prompt remediation.

Generated by OpenCVE AI on July 15, 2026 at 23:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 150.0.7871.47 or later to eliminate the flaw.
  • Enable automatic updates so new patches are applied without user action.
  • Apply input validation measures to the download handling logic (CWE‑20) to ensure that user inputs and UI gestures are validated refraining from clicking suspicious links.

Generated by OpenCVE AI on July 15, 2026 at 23:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Thu, 16 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title Inappropriate Implementation in Chrome Downloads Enables Remote Code Execution via Crafted HTML Page

Tue, 14 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Inappropriate Implementation in Chrome Downloads Enables Remote Code Execution via Crafted HTML Page

Sun, 12 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Chrome Windows Download Handling Vulnerability Enables Remote Code Execution via UI Interaction

Sat, 11 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Chrome Windows Download Handling Vulnerability Enables Remote Code Execution via UI Interaction

Fri, 10 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Insecure Handling of Downloads Enables Remote Code Execution on Windows Chrome

Thu, 09 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Insecure Handling of Downloads Enables Remote Code Execution on Windows Chrome

Wed, 08 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Inappropriate Download Handling Enabling Remote Code Execution

Tue, 07 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Inappropriate Download Handling Enabling Remote Code Execution

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Improper Download Handling in Chrome on Windows

Sun, 05 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Remote Code Execution via Improper Download Handling in Chrome on Windows

Sun, 05 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Chrome Windows Downloads UI Gesture Remote Code Execution Vulnerability

Sat, 04 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Chrome Windows Downloads UI Gesture Remote Code Execution Vulnerability

Sat, 04 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Chrome Download Handling Allows Remote Code Execution via Forged UI Gestures

Fri, 03 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Chrome Download Handling Allows Remote Code Execution via Forged UI Gestures

Thu, 02 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Chrome Windows Remote Code Execution via Crafted Download Page

Thu, 02 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Chrome Windows Remote Code Execution via Crafted Download Page

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-20
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Unsafe Download Handling Enables Arbitrary Code Execution via User Interaction
Weaknesses CWE-79
CWE-94

Wed, 01 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Unsafe Download Handling Enables Arbitrary Code Execution via User Interaction
Weaknesses CWE-79
CWE-94

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Downloads in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T03:57:02.471Z

Reserved: 2026-06-29T23:03:53.615Z

Link: CVE-2026-13925

cve-icon Vulnrichment

Updated: 2026-07-01T14:08:55.130Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-16T00:00:11Z

Weaknesses
  • CWE-20

    Improper Input Validation