What is CVE-2026-16806?
CVE-2026-16806 is a use-after-free vulnerability in the WebMCP component of Google Chrome versions prior to 150.0.7871.186. This flaw allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. Updating Chrome to the latest version is strongly recommended.
Azərbaycanca: CVE-2026-16806 Google Chrome-un 150.0.7871.186 versiyasından əvvəlki versiyalarında WebMCP komponentində aşkar edilmiş istifadədən sonra azadetmə (use-after-free) zəifliyidir. Bu qüsur uzaqdan hücum edənə xüsusi hazırlanmış HTML səhifə vasitəsilə sandbox daxilində ixtiyari kod icra etməyə imkan verir. Chrome brauzerini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-416; shared vendor: Google
FAQ2
Which version of Google Chrome should be updated to, in order to be protected against CVE-2026-16806?
It is strongly recommended to update Google Chrome to version 150.0.7871.186 or a later version to be protected against this vulnerability.
What can a remote attacker achieve by exploiting CVE-2026-16806?
This use-after-free flaw allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.