Use After Free Vulnerability in Google Chrome WebMCP Component
CVE-2026-16806

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
23 July 2026

What is CVE-2026-16806?

A vulnerability in the WebMCP component of Google Chrome allows remote attackers to execute arbitrary code within a sandbox environment. This exploitation occurs through a specially crafted HTML page that takes advantage of the use after free condition, leading to potential unauthorized access and manipulation of the system. Users are advised to update to the latest version to mitigate risks associated with this vulnerability.

Affected Version(s)

Chrome 150.0.7871.186

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.