CVE-2026-13785Patch(apple / chrome)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • macos

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 2 signals
  • Peaked 2d ago at 1 mentions (2026-07-01); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
chromemacos

1 version affected across 2 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-07-01: 1Mentions · 2026-07-03: 1Mentions · 2026-07-12: 1Patch / Workaround · 2026-07-01: 1Patch / Workaround · 2026-07-03: 1Patch / Workaround · 2026-07-12: 1Technical Details · 2026-07-01: 1Technical Details · 2026-07-12: 107-0107-0307-12
Signal classification1 categories
Patch
3100.0%
Referenced assets1 URL
Full discourse3 posts
  • kawn@kawn2020
    Patch

    #securityupdate #chrome Chrome 150.0.7871.46/.47 ・CVE-2026-13774 ・CVE-2026-13775 ・CVE-2026-13776 ・CVE-2026-13777 ・CVE-2026-13778 ・CVE-2026-13779 ・CVE-2026-13780 ・CVE-2026-13781 ・CVE-2026-13782 ・CVE-2026-13783 ・CVE-2026-13784 ・CVE-2026-13785 ・CVE-2026-13786 つづく…

    Post summary

    The tweet announces a Chrome patch (150.0.7871.46/.47) that addresses CVE-2026-13774 through CVE-2026-13786, without providing any exploitation details or technical specifics.

    1000159
    91 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Google Chrome Bluetooth Use-After-Free Sandbox Escape (CVE-2026-13785) Use-after-free in Chrome's Bluetooth component on macOS. A remote attacker who lures a user to a crafted HTML page and gets them to perform specific UI gestures can trigger the freed-object reuse and potentially escape the renderer sandbox. A sandbox escape means the attacker's code can break out of Chrome's isolated renderer process, moving toward broader compromise of the host. Affects Chrome on Mac; rated Critical by Chromium. 👉Upgrade to Chrome 150.0.7871.47.

    Post summary

    A critical use‑after‑free in Chrome’s Bluetooth component on macOS permits sandbox escape; users are advised to upgrade to Chrome 150.0.7871.47 to mitigate the vulnerability.

    00001113
    232 followersView on X
  • Windows Forum@windowsforum
    Patch

    🍎 Mac users: Chrome 150.0.7871.47 isn’t optional—CVE-2026-13785 is a critical sandbox-escape risk. Windows Chrome isn’t listed as affected, for once. Update before one bad page does the rest. https://windowsforum.com/threads/cve-2026-13785-update-chrome-for-mac-to-150-0-7871-47.437227/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #MacosSecurity #BrowserSandboxEscape #ChromeForMac #Cve202613785

    Post summary

    CVE-2026-13785 is a critical sandbox‑escape vulnerability affecting macOS Chrome; users are urged to update to version 150.0.7871.47 to mitigate the risk.

    0000068
    1.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---

Explore more