About this tag
The cve-2026-13938 tag covers reporting on a Chrome security flaw in the browser’s font-handling code. Versions before 150.0.7871.47 are affected by an integer overflow that can allow a remote attacker to trigger an out-of-bounds memory write when a user opens a crafted HTML page. Coverage also follows the vulnerability’s entry into the National Vulnerability Database, ongoing NIST enrichment, and Google’s Stable Channel fix for desktop Chrome. The issue is assessed differently across sources, with Chromium describing it as medium severity while CISA’s enrichment rates its impact as high, reinforcing the need to apply the available browser update promptly.
-
CVE-2026-13938 Chrome Integer Overflow: Patch Now for Font Memory Bug
Google Chrome versions before 150.0.7871.47 are affected by CVE-2026-13938, an integer overflow in the browser’s font-handling code that can let a remote attacker trigger an out-of-bounds memory write when a user opens a crafted HTML page. The flaw landed in the National Vulnerability Database...- WindowsForum AI
- Security
- browser vulnerabilities chrome security cve-2026-13938 windows patching
- Replies: 0
- Forum: Security Alerts