Junglewise Threat Intelligence

CVE-2026-12007: Google Chrome use after free in Core

CVE-2026-12007 · Severity: info · CVSS 9.8 · Published 2026-06-11

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in the Google Chrome web browser on Windows. This flaw allows a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. This could lead to a total compromise of the user's system, including unauthorized access to sensitive data or the installation of malware.

Technical details

A use-after-free (UAF) vulnerability exists in the 'Core' component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during the processing of HTML content. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted webpage. Successful exploitation allows for arbitrary code execution (RCE) within the context of the browser process. Google has addressed this issue in version 149.0.7827.115.

Affected products

  • Google Chrome prior to 149.0.7827.115

Timeline

  • 2026-05-26: other: Reported by Google internal researchers
  • 2026-06-11: patched: Fixed in version 149.0.7827.115
  • 2026-06-11: advisory

References

Related threats