Description
Integer overflow in Fonts in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow occurs in the font parsing logic of Google Chrome. A malicious HTML page containing tailored font data can trigger an out‑of‑bounds memory write. The overflow, classified as CWE‑472, may corrupt arbitrary memory, possibly leading to denial of service or other unintended execution paths. The description explicitly states that a remote attacker can deliver such a page.

Affected Systems

All Google Chrome desktop releases before version 150.0.7871.47 are affected. The vulnerability description does not mention mobile, so the impact appears limited to desktop builds. No other vendors or product families are listed.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS of < 1% shows a low current exploitation probability. The attack vector is likely remote, delivered through an HTML page that a user opens in an affected browser. No current evidence of exploitation and the vulnerability is not in the CISA KEV catalog.

Generated by OpenCVE AI on August 3, 2026 at 06:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.47 or newer
  • Enable automatic updates to receive future security fixes promptly
  • Deploy network‑level controls to block or filter font files from untrusted domains until the patch is applied

Generated by OpenCVE AI on August 3, 2026 at 06:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Mon, 03 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Out-of-bounds Memory Write in Chrome Font Parsing

Wed, 29 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Out-of-bounds Memory Write in Chrome Font Parsing

Sat, 25 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Memory Write via Font Parsing in Google Chrome

Tue, 21 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Memory Write via Font Parsing in Google Chrome

Thu, 16 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write via Font Parsing in Google Chrome

Tue, 14 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write via Font Parsing in Google Chrome

Tue, 14 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Integer overflow in Chrome font parsing causes out‑of‑bounds memory write

Mon, 13 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Integer overflow in Chrome font parsing causes out‑of‑bounds memory write

Sat, 11 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chrome Font Parsing Enables Out-of-Bounds Memory Write

Fri, 10 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chrome Font Parsing Enables Out-of-Bounds Memory Write

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Chrome Font Parsing Integer Overflow Allowing Out‑of‑Bounds Memory Write

Thu, 09 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Chrome Font Parsing Integer Overflow Allowing Out‑of‑Bounds Memory Write

Tue, 07 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Memory Write via Font Parsing Integer Overflow in Google Chrome

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Memory Write via Font Parsing Integer Overflow in Google Chrome

Sun, 05 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Memory Write via Integer Overflow in Chrome Font Parsing

Sun, 05 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Memory Write via Integer Overflow in Chrome Font Parsing

Sat, 04 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write via Integer Overflow in Chrome Font Parsing

Sat, 04 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write via Integer Overflow in Chrome Font Parsing

Fri, 03 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Memory Write in Chrome Fonts via Crafted HTML Page

Fri, 03 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Memory Write in Chrome Fonts via Crafted HTML Page

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Memory Write via Font Integer Overflow in Chrome

Wed, 01 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Memory Write via Font Integer Overflow in Chrome

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Integer overflow in Fonts in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-472
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T14:02:23.992Z

Reserved: 2026-06-29T23:03:56.819Z

Link: CVE-2026-13938

cve-icon Vulnrichment

Updated: 2026-07-02T13:51:59.617Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T06:45:03Z

Weaknesses
  • CWE-472

    External Control of Assumed-Immutable Web Parameter