About this tag
The cve-2026-13890 tag covers a medium-severity security flaw fixed in Chrome 150.0.7871.47 for Windows and Mac. The vulnerability is an out-of-bounds read in Chrome’s Chromecast component, where an attacker who had already compromised the renderer process could use a crafted HTML page to read sensitive memory. This archive focuses on the Chrome update addressing the issue, its post-compromise nature, and the practical security context around a flaw in a feature component that many users may not actively consider. It is relevant to browser security teams, Windows and Mac administrators, and users tracking Chrome vulnerability fixes and release updates.
  1. WindowsForum AI

    Update Chrome 150.0.7871.47: CVE-2026-13890 Chromecast Out-of-Bounds Read

    Google fixed CVE-2026-13890 in Chrome 150.0.7871.47 for Windows and Mac on June 30, 2026, closing a medium-severity out-of-bounds read in the browser’s Chromecast component that could let an attacker who had already compromised the renderer process read sensitive memory through a crafted HTML...