CVE-2026-13824
Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the rend
CVSS
7.5
High
EPSS
0.3%
p20
KEV
—
Exploit Today
6
0-100
Published: Jun 30, 2026 · Last modified: Jul 2, 2026 · CWE-20
0.2%EPSS · 30 days0.3%
2026-07-012026-07-21
Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-16422——
———Insufficient validation of untrusted input in Certificate in Google Chrome on Linux prior to 150.0.7871.182 allowed an attacker in a privileged network position to perform domain spoofing via malicious network traffic. (Chromium security severity: High)2hCVE-2026-16415——
———Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: High)2hCVE-2026-16414——
———Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: High)2hCVE-2026-648778.4 HIG—
———An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.5hCVE-2026-15792——
———A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.7hCVE-2026-157248.7 HIG—
———In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server.7h