Junglewise Threat Intelligence

CVE-2026-12028: Google Chrome use after free in GPU component

CVE-2026-12028 · Severity: info · CVSS 8.8 · Published 2026-06-11

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its graphics processing component could allow a remote attacker to bypass the browser's security 'sandbox' after first compromising a website's rendering process. If successfully exploited via a malicious webpage, this could allow an attacker to gain unauthorized access to the underlying Android operating system and user data.

Technical details

A use-after-free (UAF) vulnerability exists in the GPU component of Google Chrome on Android. The flaw is triggered when the browser incorrectly manages memory lifecycle during graphics processing. An attacker who has already achieved code execution within the sandboxed renderer process can leverage this UAF to escape the sandbox and execute arbitrary code with elevated privileges on the host operating system. Exploitation requires the victim to navigate to a specially crafted HTML page. Google has addressed this in version 149.0.7827.115.

Affected products

  • Google Chrome prior to 149.0.7827.115

Timeline

  • 2026-05-28: disclosed: Reported to Chrome by Google internal researchers
  • 2026-06-11: patched: Fixed in version 149.0.7827.115
  • 2026-06-11: advisory: Public advisory published by Google and NVD

References

Related threats