Junglewise Threat Intelligence

CVE-2026-12462: Google Chrome use after free in Media

CVE-2026-12462 · Severity: high · CVSS 7.5 · Published 2026-06-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the media handling component of Google Chrome. If a user visits a specially crafted website, an attacker who has already partially compromised the browser's rendering process could execute unauthorized code on the user's computer. While this code execution is restricted by a security sandbox, it could still lead to further system compromise or data theft.

Technical details

A use-after-free (UAF) vulnerability exists in the Media component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory during the processing of media content. An attacker can exploit this by enticing a user to visit a malicious HTML page. A successful exploit requires the attacker to have already compromised the renderer process, at which point they can achieve arbitrary code execution within the confines of the browser's sandbox. This vulnerability was addressed in Chrome version 149.0.7827.155 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 149.0.7827.155

Timeline

  • 2026-05-29: disclosed: Reported to Google by internal/external researchers
  • 2026-06-16: patched: Stable channel update released for desktop
  • 2026-06-17: advisory: NVD and official advisory published

References

Related threats