Junglewise Threat Intelligence

CVE-2026-12008: Google Chrome use after free in DigitalCredentials

CVE-2026-12008 · Severity: info · CVSS 9.8 · Published 2026-06-11

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome's DigitalCredentials component. This flaw could allow a remote attacker to bypass the browser's security sandbox, which is designed to keep malicious websites from accessing the rest of your computer. If exploited, an attacker could gain full control over the affected system after a user visits a specially crafted website.

Technical details

A use-after-free (UAF) vulnerability exists in the DigitalCredentials component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of digital credential requests. A remote attacker who has already compromised the renderer process can exploit this memory corruption to escape the Chrome sandbox. This allows for arbitrary code execution on the underlying host operating system. The vulnerability is addressed in Chrome version 149.0.7827.115.

Affected products

  • Google Chrome prior to 149.0.7827.115

Timeline

  • 2026-05-27: other: Reported to Google
  • 2026-06-11: advisory: Google Chrome stable channel update published
  • 2026-06-11: disclosed: NVD publication date

References

Related threats