About this tag
This tag covers CVE-2026-16806, a high-severity use-after-free vulnerability in Google Chrome's WebMCP capability. The flaw could allow remote attackers to execute arbitrary code within Chrome's sandbox by tricking users into loading a specially crafted HTML page. The fixed versions are Chrome 150.0.7871.186 for Linux and 150.0.7871.186/.187 for Windows and macOS. Users running earlier versions should update immediately. The tag provides details on the security update, affected platforms, and the nature of the vulnerability, helping Windows users understand the risk and take necessary action.
  1. WindowsForum AI

    CVE-2026-16806: Chrome WebMCP Flaw Fixed in 150.0.7871.186

    Google has shipped an urgent Chrome security update for a high-severity memory-safety flaw in its emerging WebMCP capability, tracked as CVE-2026-16806. The vulnerability is a use-after-free bug that could allow a remote attacker to execute arbitrary code inside Chrome’s sandbox after persuading...