Junglewise Threat Intelligence

CVE-2026-12452: Google Chrome use after free in Downloads

CVE-2026-12452 · Severity: high · CVSS 8.8 · Published 2026-06-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android is a popular mobile web browser. A security vulnerability in the browser's download management component could allow a malicious website to corrupt the app's memory. If exploited, this could lead to the browser crashing or potentially allow an attacker to gain unauthorized access to data or execute malicious code on the device.

Technical details

A use-after-free vulnerability exists in the Downloads component of Google Chrome on Android. The flaw is triggered when the browser incorrectly manages memory during download operations, which can be reached by a remote attacker via a specially crafted HTML page. Successful exploitation requires user interaction (visiting the malicious page) and can lead to heap corruption, potentially allowing for arbitrary code execution within the browser's sandbox. Google has addressed this issue in version 149.0.7827.155 and later.

Affected products

  • Google Chrome prior to 149.0.7827.155

Timeline

  • 2026-05-21: disclosed: Reported to Chrome by Google researchers
  • 2026-06-16: patched: Stable channel update released
  • 2026-06-17: advisory: NVD publication date

References

Related threats