Junglewise Threat Intelligence

CVE-2026-12440: Google Chrome use after free in DigitalCredentials

CVE-2026-12440 · Severity: critical · CVSS 9.6 · Published 2026-06-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome's Digital Credentials component on Windows. This flaw could allow a malicious website to break out of the browser's security sandbox, which is designed to keep web content isolated from the rest of the computer. If exploited, an attacker could potentially gain unauthorized access to the underlying operating system, compromising user data and system integrity.

Technical details

A use-after-free (UAF) vulnerability exists in the DigitalCredentials component of Google Chrome for Windows. The flaw is triggered when the browser incorrectly manages memory during the handling of digital credentials, allowing a remote attacker to execute arbitrary code. By enticing a user to visit a specially crafted HTML page, an attacker can exploit this memory corruption to escape the Chromium sandbox and execute commands with the privileges of the logged-in user. This vulnerability is addressed in Chrome version 149.0.7827.155.

Affected products

  • Google Chrome Prior to 149.0.7827.155

Timeline

  • 2026-06-03: other: Reported to Google
  • 2026-06-16: patched: Stable channel update released
  • 2026-06-17: disclosed: Public advisory published

References

Related threats