Junglewise Threat Intelligence

CVE-2026-12455: Google Chrome use after free in Tab Strip

CVE-2026-12455 · Severity: high · CVSS 7.5 · Published 2026-06-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contains a security flaw in its tab management component. An attacker could exploit this by tricking a user into visiting a malicious website and performing specific mouse or keyboard actions. If successful, this could allow the attacker to crash the browser or potentially run unauthorized code on the user's computer, compromising personal data and system security.

Technical details

A use-after-free (UAF) vulnerability exists in the Tab Strip component of Google Chrome. The flaw is triggered when a remote attacker convinces a user to perform specific UI gestures while visiting a maliciously crafted HTML page. This interaction leads to heap corruption due to the browser attempting to access memory that has already been freed. Successful exploitation could allow for remote code execution within the browser's sandbox or a denial-of-service condition. The issue is resolved in Google Chrome version 149.0.7827.155 for Linux and 149.0.7827.155/.156 for Windows and Mac.

Affected products

  • Google Chrome prior to 149.0.7827.155

Timeline

  • 2026-05-27: disclosed: Reported to Google by internal/external researchers
  • 2026-06-16: patched: Stable channel update released
  • 2026-06-17: advisory: NVD and Chrome release blog published

References

Related threats