Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-13036

Опубликовано: 24 июн. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Blink, a rendering engine used in Google Chrome. This vulnerability, a 'use after free' error, allows a remote attacker to execute arbitrary code within the browser's security sandbox. This can be achieved by enticing a user to visit a specially crafted HTML page, leading to a high-severity security risk.

Отчет

This Important use-after-free flaw in the Blink component of Chromium-based browsers allows a remote attacker to execute arbitrary code within the browser's sandbox. Exploitation requires user interaction, such as visiting a malicious HTML page. The vulnerability's impact is contained by the browser's sandbox, limiting direct system compromise.

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=2492499chromium-browser: chromium-browser: Use after free in Blink

EPSS

Процентиль: 22%
0.00293
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
около 2 месяцев назад

Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

msrc
около 2 месяцев назад

Chromium: CVE-2026-13036 Use after free in Blink

CVSS3: 8.8
debian
около 2 месяцев назад

Use after free in Blink in Google Chrome prior to 149.0.7827.197 allow ...

EPSS

Процентиль: 22%
0.00293
Низкий

8.8 High

CVSS3