What is CVE-2026-16804?
A use after free vulnerability in the Input component of Google Chrome versions prior to 150.0.7871.186 allowed a remote attacker who compromised the renderer process to potentially escape the sandbox via a crafted HTML page. Updating Chrome to the specified version is required to mitigate this High severity issue.
Azərbaycanca: CVE-2026-16804 Google Chrome-un 150.0.7871.186 versiyasından əvvəlki versiyalarında Input komponentində 'use after free' zəifliyidir. Bu, renderer prosesini ələ keçirmiş uzaqdan hücumçuya xüsusi hazırlanmış HTML səhifə vasitəsilə sandbox mühitindən çıxmağa imkan verir. Chrome brauzerini qeyd olunan versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-416; shared vendor: Google
FAQ2
Which versions of Google Chrome are affected by CVE-2026-16804?
This vulnerability affects all versions of Google Chrome prior to 150.0.7871.186.
What type of vulnerability is CVE-2026-16804 and what can an attacker achieve?
It is a use after free vulnerability in the Input component. A remote attacker who has compromised the renderer process can potentially escape the sandbox via a crafted HTML page.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.