Junglewise Threat Intelligence

CVE-2026-12467: Google Chrome use after free in Extensions

CVE-2026-12467 · Severity: high · CVSS 8.3 · Published 2026-06-17

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the browser's Extensions component could allow a remote attacker to bypass security protections (the 'sandbox') that normally isolate the browser from the rest of the computer. If exploited, this could allow an attacker to gain unauthorized access to the underlying operating system or user data after they have already gained a foothold in the browser's rendering process.

Technical details

A use-after-free (UAF) vulnerability exists in the Extensions component of Google Chrome. The flaw is triggered when the browser incorrectly manages memory for extension-related objects, allowing an attacker to reference memory after it has been freed. To exploit this, a remote attacker must first compromise the renderer process (typically via a separate vulnerability) and then entice a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to escape the Chrome sandbox and execute arbitrary code with the privileges of the browser process. This issue was addressed in version 149.0.7827.155.

Affected products

  • Google Chrome prior to 149.0.7827.155

Timeline

  • 2026-06-05: other: Reported to Google
  • 2026-06-16: patched: Stable channel update released
  • 2026-06-17: disclosed: Public advisory published

References

Related threats