Junglewise Threat Intelligence

CVE-2026-12442: Google Chrome for Android use after free in Passwords

CVE-2026-12442 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

A critical security vulnerability has been identified in Google Chrome for Android's password management component. An attacker could exploit this flaw by tricking a user into visiting a specially crafted website, potentially allowing the attacker to take control of the device or execute unauthorized commands. This could lead to the theft of sensitive information, including saved passwords, or a complete compromise of the browser session.

Technical details

A use-after-free (UAF) vulnerability exists in the Passwords component of Google Chrome for Android. The flaw is triggered when the browser incorrectly manages memory during the handling of password-related data, which can be exploited by a remote attacker via a specially crafted HTML page. Successful exploitation requires minimal user interaction (visiting a malicious site) and can lead to arbitrary code execution (ACE) within the context of the browser process. Google has addressed this in version 149.0.7827.155 and later.

Affected products

  • Google Chrome prior to 149.0.7827.155

Timeline

  • 2026-06-09: disclosed: Reported to Google internally
  • 2026-06-16: patched: Stable channel update released
  • 2026-06-17: advisory: NVD publication date

References

Related threats