Description
Integer overflow in Fonts in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow in Google Chrome allows a specially crafted HTML page to cause the browser to write data beyond intended memory bounds. This out‑of‑bounds memory write can corrupt memory, leading to denial of service or other unintended behavior. The vulnerability exploits the numeric overflow in handling font metrics and is classified as CWE‑472.

Affected Systems

Google Chrome desktop builds released before version 150.0.7871.47 are affected; it is currently unspecified whether mobile or other platform builds are impacted. The parsing code in the desktop release of Chrome.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS score of less than 1% suggests a low probability of exploitation at present. The likely attack vector is a remote attacker delivering a crafted HTML page that includes malicious font data, as inferred from the description of the vulnerability. It is inferred from the lack of public reports that active exploitation has not yet been observed. The resulting out‑of‑bounds write could corrupt memory, potentially leading to denial of service or other unintended behavior.

Generated by OpenCVE AI on July 21, 2026 at 16:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.47 or newer
  • Enable automatic updates to receive future security fixes promptly
  • Deploy network‑level controls to block or filter font files from untrusted domains until the patch is applied

Generated by OpenCVE AI on July 21, 2026 at 16:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Thu, 16 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write via Font Parsing in Google Chrome

Tue, 14 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write via Font Parsing in Google Chrome

Tue, 14 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Integer overflow in Chrome font parsing causes out‑of‑bounds memory write

Mon, 13 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Integer overflow in Chrome font parsing causes out‑of‑bounds memory write

Sat, 11 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chrome Font Parsing Enables Out-of-Bounds Memory Write

Fri, 10 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chrome Font Parsing Enables Out-of-Bounds Memory Write

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Chrome Font Parsing Integer Overflow Allowing Out‑of‑Bounds Memory Write

Thu, 09 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Chrome Font Parsing Integer Overflow Allowing Out‑of‑Bounds Memory Write

Tue, 07 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Memory Write via Font Parsing Integer Overflow in Google Chrome

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Memory Write via Font Parsing Integer Overflow in Google Chrome

Sun, 05 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Memory Write via Integer Overflow in Chrome Font Parsing

Sun, 05 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Memory Write via Integer Overflow in Chrome Font Parsing

Sat, 04 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write via Integer Overflow in Chrome Font Parsing

Sat, 04 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Write via Integer Overflow in Chrome Font Parsing

Fri, 03 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Memory Write in Chrome Fonts via Crafted HTML Page

Fri, 03 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Memory Write in Chrome Fonts via Crafted HTML Page

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Memory Write via Font Integer Overflow in Chrome

Wed, 01 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Out‑of‑Bounds Memory Write via Font Integer Overflow in Chrome

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Integer overflow in Fonts in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-472
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T14:02:23.992Z

Reserved: 2026-06-29T23:03:56.819Z

Link: CVE-2026-13938

cve-icon Vulnrichment

Updated: 2026-07-02T13:51:59.617Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-16T12:30:03Z

Weaknesses
  • CWE-472

    External Control of Assumed-Immutable Web Parameter