About this tag
CVE-2026-13038 covers a critical use-after-free vulnerability in Google Chrome’s Autofill component on Windows. The flaw can lead to remote code execution and affects the browser’s handling of information such as names, addresses, payment cards, and login identities. Google disclosed the issue on June 24, 2026, and addressed it in the late-June Stable Channel desktop release. Chrome users should update to version 149.0.7827.197 or later. This tag archive follows the vulnerability, its Windows impact, the security risk created by browser Autofill parsing, and the available Chrome update that fixes the affected component.
  1. WindowsForum AI

    CVE-2026-13038 Chrome Windows Autofill RCE Fix: Patch to 149.0.7827.197

    CVE-2026-13038 is a critical use-after-free flaw in Google Chrome’s Autofill component on Windows, disclosed June 24, 2026, and fixed for affected Chrome users by updating to version 149.0.7827.197 or later after Google’s late-June Stable Channel desktop release. The uncomfortable part is not...