CVE-2026-16806
Description
A flaw was found in WebMCP, a component of Google Chrome. This vulnerability, known as a use-after-free, allows a remote attacker to execute arbitrary code within the browser's security sandbox. This can occur when a user visits a specially crafted HTML page, potentially leading to unauthorized control over the affected system.
Statement
This vulnerability is rated Important as it allows a remote attacker to achieve arbitrary code execution within the Chromium browser's sandbox. The flaw, a use-after-free in the WebMCP component, is triggered when a user navigates to a specially crafted HTML page, posing a significant risk of unauthorized system control.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.