Out-of-bounds write in Google Chromium - CVE-2026-16807

 

Out-of-bounds write in Google Chromium - CVE-2026-16807

Published: July 25, 2026


Vulnerability identifier: #VU139354
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-16807
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted HTML content in Codecs. A remote attacker can create a specially crafted web page, trick the victim into opening it, trigger out-of-bounds write and execute arbitrary code on the target system.


Affected software

Google Chromium
Microsoft Edge
Google Chrome
Prisma Access Browser
Debian Linux
Fedora
chromium
chromium (Debian package)

How to mitigate CVE-2026-16807

Install update from vendor's website.

Google Chromium - update to 150.0.7871.186
Microsoft Edge - update to 150.0.4078.99
Google Chrome - update to 150.0.7871.186
chromium - addressed in versions 150.0.7871.186-1.el9, 150.0.7871.186-1.el10_2, 150.0.7871.186-1.el10_3, 150.0.7871.186-1.fc43, 150.0.7871.186-1.fc44
Prisma Access Browser - update to 150.49.8.187
chromium (Debian package) - update to 151.0.7922.71-1~deb13u1

External References

Related Security Bulletins