Junglewise Threat Intelligence

CVE-2026-12437: Google Chrome use after free in WebShare

CVE-2026-12437 · Severity: high · CVSS 8.3 · Published 2026-06-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's WebShare feature could allow an attacker to bypass the browser's security sandbox. This component is responsible for sharing content from web pages to other apps or services. If exploited, an attacker could gain unauthorized access to the underlying Windows operating system, potentially leading to full system compromise or data theft.

Technical details

A use-after-free (UAF) vulnerability exists in the WebShare component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during sharing operations. An attacker who has already compromised the renderer process can exploit this issue via a specially crafted HTML page to achieve a sandbox escape. This allows the attacker to execute arbitrary code outside of the restricted browser environment on the host operating system. The vulnerability is addressed in Chrome version 149.0.7827.155.

Affected products

  • Google Chrome prior to 149.0.7827.155

Timeline

  • 2026-05-25: other: Reported by Google researchers
  • 2026-06-16: patched: Stable channel update released
  • 2026-06-17: advisory: NVD and CISA-ADP enrichment published

References

Related threats