CVE-2026-13940: exploitation status and patch state
CVE-2026-13940 · CVSS 6.5 MEDIUM · EPSS <1% · patch available
Uninitialized Use in Cast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via malicious network traffic. (Chromium security severity: Medium)
Is CVE-2026-13940 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at <1%.
Public exploit code: none found in monitored sources.