Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-16806

Опубликовано: 23 июл. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

A flaw was found in WebMCP, a component of Google Chrome. This vulnerability, known as a use-after-free, allows a remote attacker to execute arbitrary code within the browser's security sandbox. This can occur when a user visits a specially crafted HTML page, potentially leading to unauthorized control over the affected system.

Отчет

This vulnerability is rated Important as it allows a remote attacker to achieve arbitrary code execution within the Chromium browser's sandbox. The flaw, a use-after-free in the WebMCP component, is triggered when a user navigates to a specially crafted HTML page, posing a significant risk of unauthorized system control.

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=2506637chromium-browser: Chromium: Arbitrary code execution via use after free vulnerability in WebMCP

EPSS

Процентиль: 33%
0.00398
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
18 дней назад

Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.8
nvd
18 дней назад

Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

msrc
17 дней назад

Chromium: CVE-2026-16806 Use after free in WebMCP

CVSS3: 8.8
debian
18 дней назад

Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allo ...

CVSS3: 8.8
github
18 дней назад

Use after free in WebMCP in Google Chrome prior to 150.0.7871.186 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

EPSS

Процентиль: 33%
0.00398
Низкий

8.8 High

CVSS3