CVE-2026-13854: High Use after free in Ozone
Chromium: CVE-2026-13854 Use after free in Ozone
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 150.0.4078.48 - Upgrade
Upgrade
Google Chrome (Chromium-based)to a version that resolves this vulnerability.Fixed in 150.0.7871.47 - Compensating control
If immediate patching is not possible, mitigate the impact by preventing or limiting renderer compromise (e.g., reduce exposure by disabling untrusted content/HTML rendering paths in the browser and restricting access to browsing of untrusted pages) until Google Chrome on Linux is updated to 150.0.7871.47 or later.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-19141
- CVE-2026-13281
- CVE-2026-19155
- CVE-2026-19175
- CVE-2026-12446
- CVE-2026-19153
- CVE-2026-19166
- CVE-2026-15123
- CVE-2026-17680
- CVE-2026-12460
- CVE-2026-9126
- CVE-2026-12456
- CVE-2026-12459
- CVE-2026-15905
- CVE-2026-15127
- CVE-2026-17657
- CVE-2026-15107
- CVE-2026-15118
- CVE-2026-15108
- CVE-2026-15116
- CVE-2026-12451
- CVE-2026-12015
- CVE-2026-15902
- CVE-2026-15778
- CVE-2026-15119
- CVE-2026-15121
- CVE-2026-13031
- CVE-2026-13036
- CVE-2026-16805
- CVE-2026-13853
- CVE-2026-15111
- CVE-2026-12017
- CVE-2026-13023
- CVE-2026-13026
- CVE-2026-13024
- CVE-2026-12019
- CVE-2026-10970
- CVE-2026-19140
- CVE-2026-15114
- CVE-2026-19156
- CVE-2026-16423
- CVE-2026-19159
- CVE-2026-11672
- CVE-2026-19157
- CVE-2026-12455
- CVE-2026-17650
- CVE-2026-10956
- CVE-2026-11691
- CVE-2026-12012
- CVE-2026-11684
- CVE-2026-12014
Frequently Asked Questions
What is the severity of CVE-2026-13854?
CVE-2026-13854 has a critical severity rating of 9.6 based on the CVSS 3.1 scoring system.
What type of vulnerability is CVE-2026-13854?
CVE-2026-13854 is classified as a Use After Free vulnerability found in Ozone within Google Chrome.
How do I fix CVE-2026-13854?
To fix CVE-2026-13854, ensure that you update Google Chrome or Microsoft Edge to the latest version above 150.0.7871.47.
Which software is affected by CVE-2026-13854?
CVE-2026-13854 affects Google Chrome on Linux and Microsoft Edge, both of which are Chromium-based browsers.
What are the risks associated with CVE-2026-13854?
The risks of CVE-2026-13854 include potential exploitation that can lead to data leakage and unauthorized access due to its Use After Free nature.