Skip to content
COOEY

EXPOSURES › CVE-2026-13781

CVE-2026-13781

CRITICAL
DETAIL
SourceNVD · cve Published2026-06-30 CVSS9.6 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-13781 ↗
SHAME 35/100

Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

▸ RECOMMENDED ACTION  Critical severity — schedule patching of the affected products.

DESCRIPTION

Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

AFFECTED FEDRAMP PRODUCTS · 6
PRODUCTSTATUS
Azure Commercial Cloud
Microsoft
Authorized
Azure Government (includes Dynamics 365)
Microsoft
Authorized
Google Services (Google Cloud Platform Products and underlying Infrastructure)
Google
Authorized
Google Workspace
Google
Authorized
Microsoft Office 365 GCC High
Microsoft
In Process
Office 365 Multi-Tenant & Supporting Services
Microsoft
Authorized