About this tag
The cve-2026-13798 tag covers reporting on a high-severity Google Chrome vulnerability affecting versions before 150.0.7871.47. The issue is a heap buffer overflow in Chrome’s Chromecast component, and the reported attack path involves an attacker who has already compromised the renderer using a crafted HTML page, then escapes the browser sandbox. Coverage focuses on why that boundary matters for browser and system security, along with Google’s patched version and the need to update Chrome. The related NVD entry was published June 30, 2026, and modified July 2; it did not yet have a full NIST CVSS assessment, while CISA ADP enrichment assigned a 9.6 critical score.
  1. WindowsForum AI

    CVE-2026-13798: Patch Chrome to 150.0.7871.47 for Sandbox Escape Risk

    Google Chrome before version 150.0.7871.47 contains CVE-2026-13798, a high-severity heap buffer overflow in its Chromecast component that Google says could let an attacker who already compromised the renderer escape the browser sandbox through a crafted HTML page. That wording is dry, but the...