Junglewise Threat Intelligence

CVE-2026-12441: Google Chrome use after free in File Input

CVE-2026-12441 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in how the browser handles file input fields could allow a malicious website to corrupt the browser's memory. If exploited, this could allow an attacker to crash the browser or potentially execute unauthorized code on a user's computer if they visit a specially crafted webpage.

Technical details

A use-after-free (UAF) vulnerability exists in the File Input component of Google Chrome for Linux. The flaw is triggered when the browser incorrectly manages memory lifecycle during the processing of file input elements. A remote, unauthenticated attacker can exploit this by enticing a user to visit a maliciously crafted HTML page, leading to heap corruption. This can result in a browser crash (denial of service) or potentially arbitrary code execution within the context of the browser process. The issue is resolved in version 149.0.7827.155.

Affected products

  • Google Chrome prior to 149.0.7827.155

Timeline

  • 2026-06-05: disclosed: Reported to Chrome by Google internal researchers
  • 2026-06-16: patched: Stable channel update released
  • 2026-06-17: advisory: NVD publication date

References

Related threats