CVE-2026-13036

Description

A flaw was found in Blink, a rendering engine used in Google Chrome. This vulnerability, a 'use after free' error, allows a remote attacker to execute arbitrary code within the browser's security sandbox. This can be achieved by enticing a user to visit a specially crafted HTML page, leading to a high-severity security risk.

Statement

This Important use-after-free flaw in the Blink component of Chromium-based browsers allows a remote attacker to execute arbitrary code within the browser's sandbox. Exploitation requires user interaction, such as visiting a malicious HTML page. The vulnerability's impact is contained by the browser's sandbox, limiting direct system compromise.

Frequently Asked Questions

Want to get errata notifications? Sign up here.