CVE-2026-13811
Use after free in IME in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a cra
CVSS
8.8
High
EPSS
0.4%
p32
KEV
—
Exploit Today
10
0-100
Published: Jun 30, 2026 · Last modified: Jul 2, 2026 · CWE-416
0.4%EPSS · 30 days0.4%
2026-08-232026-09-21
Use after free in IME in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-940849.4 CRI34.1%
——10Suricata before 8.0.7 has an Http2ThreadMultiBuf use-after-free when a transaction is inspected by rules that use http.response_header with and without a transform.2dCVE-2026-940553.7 LOW24.3%
——7Exim before 4.100.1, when certain non-default TLS settings are used with GnuTLS, has a use-after-free.4hCVE-2026-880978.1 HIG12.7%
——4Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.2dCVE-2026-935862.9 LOW1.7%
——1ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a use-after-free vulnerability in the ImagesToBlob method, caused by a pointer that is not updated correctly. Exploitation may result in a limited availability impact (e.g., a crash of the affected process). The issue is fixed in versions 7.1.2-31 and 6.9.13-56.3dCVE-2026-933828.8 HIG31.1%
——9Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)3dCVE-2026-933749.6 CRI29.1%
——9Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)5h