Junglewise Threat Intelligence

CVE-2026-13026: Google Chrome use after free in Digital Credentials

CVE-2026-13026 · Severity: info · CVSS 8.8 · Published 2026-06-24

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome on macOS is vulnerable to a security flaw in its Digital Credentials component, which handles digital identity and credential sharing. An attacker could exploit this by tricking a user into visiting a specially crafted website, potentially leading to a browser crash or the execution of unauthorized code. This could allow an attacker to compromise the user's data or gain control over the browser session.

Technical details

A use-after-free (UAF) vulnerability exists in the Digital Credentials component of Google Chrome for macOS. The flaw is triggered when the browser incorrectly manages memory during the processing of digital credentials, leading to heap corruption. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious HTML page. Successful exploitation could lead to arbitrary code execution within the context of the browser process or a denial-of-service (DoS) condition. The issue is resolved in Google Chrome version 149.0.7827.197 for Mac.

Affected products

  • Google Chrome prior to 149.0.7827.197

Timeline

  • 2026-06-03: disclosed: Reported to Google by internal researchers
  • 2026-06-23: patched: Stable channel update released for Desktop
  • 2026-06-24: advisory: NVD publication date

References

Related threats