Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-13805

CVE-2026-13805: Google Chrome Use-After-Free Vulnerability

CVE-2026-13805 is a use-after-free vulnerability in Google Chrome's GFX component on Mac that enables remote code execution through malicious HTML pages. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-13805 Overview

CVE-2026-13805 is a use-after-free vulnerability in the graphics (GFX) component of Google Chrome on macOS. The flaw affects Chrome versions prior to 150.0.7871.47 and stems from improper memory management in the renderer's graphics subsystem [CWE-416]. A remote attacker can trigger the condition by convincing a user to load a crafted HTML page. Successful exploitation allows arbitrary code execution in the context of the browser process, breaking the confidentiality, integrity, and availability of the affected system.

Critical Impact

Remote attackers can achieve arbitrary code execution on macOS endpoints running vulnerable Chrome builds by luring users to a malicious web page.

Affected Products

  • Google Chrome on macOS prior to 150.0.7871.47
  • Apple macOS hosts running the vulnerable Chrome build
  • Chromium-based downstream browsers using the same GFX code path

Discovery Timeline

  • 2026-06-30 - CVE-2026-13805 published to NVD
  • 2026-07-02 - Last updated in NVD database

Technical Details for CVE-2026-13805

Vulnerability Analysis

The vulnerability is a use-after-free condition in Chrome's GFX component, which handles graphics rendering primitives inside the browser. Use-after-free flaws occur when a program continues to reference memory after it has been freed. An attacker can reclaim that memory region with controlled data before the dangling pointer is dereferenced. In Chrome's renderer, this typically enables corruption of C++ object virtual tables or function pointers. The attacker then redirects control flow to attacker-controlled code, achieving arbitrary code execution within the renderer sandbox. Chained with a sandbox escape, the flaw can be used to compromise the underlying macOS host. Chromium engineers rated the security severity as High, and full technical details are tracked in the Chromium Issue Tracker Entry.

Root Cause

The root cause is improper object lifetime management inside the GFX subsystem. A GFX object is released while another code path retains a reference. Subsequent access to that reference dereferences memory that may be under attacker control, yielding memory corruption classified as [CWE-416].

Attack Vector

Exploitation is network-based and requires user interaction. The attacker hosts a crafted HTML page, typically served from an attacker-controlled domain or delivered through phishing, malvertising, or a compromised site. When the victim visits the page in a vulnerable Chrome build on macOS, JavaScript and rendering primitives trigger the use-after-free in GFX. See the Google Chrome Release Update for the vendor advisory.

No public proof-of-concept or exploit is currently listed for this CVE, and it is not present on the CISA Known Exploited Vulnerabilities catalog.

Detection Methods for CVE-2026-13805

Indicators of Compromise

  • Chrome renderer process crashes on macOS with signals consistent with heap corruption or invalid memory access in GFX code paths.
  • Unexpected child processes spawned from Google Chrome Helper (Renderer) on macOS endpoints.
  • Outbound connections from Chrome helper processes to previously unseen domains immediately after page loads.
  • Chrome installations reporting version strings earlier than 150.0.7871.47 in enterprise inventory.

Detection Strategies

  • Inventory installed Chrome versions across the macOS fleet and flag hosts running builds below 150.0.7871.47.
  • Monitor macOS crash reports (ReportCrash) for repeated Chrome renderer faults referencing GFX or Skia modules.
  • Alert on anomalous process lineage where a Chrome helper process executes shells, osascript, or file-writing utilities.
  • Correlate web proxy logs with endpoint telemetry to identify users who visited high-risk domains around the time of renderer crashes.

Monitoring Recommendations

  • Ingest Chrome version telemetry and macOS process events into a centralized data lake for continuous exposure assessment.
  • Track browser child-process execution chains and file modifications under user home directories after browsing sessions.
  • Baseline expected network destinations for Chrome helper processes and alert on deviations.

How to Mitigate CVE-2026-13805

Immediate Actions Required

  • Update Google Chrome on all macOS endpoints to version 150.0.7871.47 or later without delay.
  • Enforce automatic Chrome updates through MDM policies such as Jamf, Kandji, or Intune for macOS.
  • Restart Chrome after updating so the patched binary is loaded across all renderer processes.
  • Audit third-party Chromium-based browsers on macOS and update them once vendors ship the corresponding fix.

Patch Information

Google released the fix in the Stable channel update documented in the Google Chrome Release Update. Upgrading to Chrome 150.0.7871.47 or later on macOS eliminates the vulnerable GFX code path.

Workarounds

  • Restrict browsing to trusted sites through web filtering or DNS controls until patching is complete.
  • Disable Chrome for high-risk users on unpatched macOS endpoints and route them to a patched browser.
  • Apply the principle of least privilege on macOS accounts so a compromised renderer has minimal reach.
bash
# Verify Chrome version on macOS
/Applications/Google\ Chrome.app/Contents/MacOS/Google\ Chrome --version

# Force policy-managed update via defaults (example)
sudo defaults write /Library/Preferences/com.google.Keystone.Agent checkInterval -int 3600

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.