Junglewise Threat Intelligence

CVE-2026-12439: Google Chrome use after free in Digital Credentials

CVE-2026-12439 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's Digital Credentials component, which handles how the browser manages digital identity documents. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially allowing them to crash the browser or execute unauthorized code. This could lead to the theft of sensitive information or a complete compromise of the user's browsing session.

Technical details

A use-after-free (UAF) vulnerability exists in the Digital Credentials component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of digital credential requests. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious HTML page, leading to heap corruption. Successful exploitation could allow for arbitrary code execution within the context of the browser process. Google has addressed this in version 149.0.7827.155 and later.

Affected products

  • Google Chrome prior to 149.0.7827.155

Timeline

  • 2026-06-03: other: Reported to Google by internal researchers
  • 2026-06-16: patched: Stable channel update released for Desktop
  • 2026-06-17: disclosed: Public advisory published

References

Related threats