Junglewise Threat Intelligence

CVE-2026-12445: Google Chrome use after free in Extensions

CVE-2026-12445 · Severity: high · CVSS 7.5 · Published 2026-06-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in the browser's extension system could allow a malicious extension to corrupt the computer's memory. If a user is tricked into installing a specially crafted malicious extension, an attacker could potentially take control of the browser or cause it to crash.

Technical details

A use-after-free (UAF) vulnerability exists in the Extensions framework of Google Chrome. The flaw is rooted in improper memory management where the browser continues to use a memory pointer after it has been freed, leading to potential heap corruption. To exploit this, an attacker must successfully trick a user into installing a malicious, specially crafted Chrome Extension (user interaction required). Successful exploitation could lead to arbitrary code execution within the context of the browser process. This issue was addressed in Chrome version 149.0.7827.155.

Affected products

  • Google Chrome prior to 149.0.7827.155

Timeline

  • 2026-05-14: disclosed: Reported to Google by internal/external researchers.
  • 2026-06-16: patched: Stable channel update released.
  • 2026-06-17: advisory: NVD and Chrome release notes published.

References

Related threats