CVE-2026-13940: exploitation status and patch state

CVE-2026-13940 · CVSS 6.5 MEDIUM · EPSS <1% · patch available

Uninitialized Use in Cast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via malicious network traffic. (Chromium security severity: Medium)

Is CVE-2026-13940 exploited?

Which products and versions are affected?

No affected package list recorded here yet.

Is there a patch?

What PlainSec published about CVE-2026-13940

Primary sources

What this record does not say

KEV and EPSS are re-checked daily. Record last updated 2026-08-14.