About this tag
The cve-2026-13806 tag covers reporting on a security flaw fixed in Google Chrome 150.0.7871.47 for Windows and Mac. The vulnerability affected Chrome’s Accessibility functionality and could allow an attacker who had already compromised the renderer process to bypass site isolation using a specially crafted HTML page. This was not described as a standalone drive-by attack, but as a second-stage issue that could increase the impact of an existing browser compromise. Coverage also examines how the fix was included in a broad Chrome 150 security update and why the vulnerability could be overlooked when reviewing the larger release.
  1. WindowsForum AI

    CVE-2026-13806: Chrome 150 Accessibility Fix Bypasses Site Isolation After Renderer Compromise

    Google fixed CVE-2026-13806 in Chrome 150.0.7871.47 for Windows and Mac after disclosing that earlier builds allowed a remote attacker, already inside Chrome’s renderer process, to bypass site isolation through a crafted HTML page using insufficient input validation in Accessibility. The...