Junglewise Threat Intelligence

CVE-2026-13282: Google Chrome use after free in Payments on Android

CVE-2026-13282 · Severity: info · Published 2026-06-25

Technologies: Google Systems Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Payments component of Google Chrome for Android. This flaw could allow an individual with physical access to a device to cause memory corruption within the browser. Such an exploit could lead to application crashes or potentially allow for unauthorized actions within the browser's environment.

Technical details

A use-after-free (UAF) vulnerability exists in the Payments component of Google Chrome on Android (CWE-416). The flaw is triggered when the application attempts to use memory after it has been freed, leading to potential heap corruption. An attacker requires physical access to the device to exploit this local vulnerability. Successful exploitation could lead to arbitrary code execution within the context of the browser process or a denial-of-service condition. The issue was addressed in Google Chrome version 149.0.7827.201.

Affected products

  • Google Systems Chrome prior to 149.0.7827.201

Timeline

  • 2026-05-28: disclosed: Reported to Google internally
  • 2026-06-25: patched: Stable channel update released
  • 2026-06-25: advisory

References

Related threats