Junglewise Threat Intelligence

CVE-2026-6319: Google Chrome for Android use after free in Payments

CVE-2026-6319 · Severity: high · CVSS 7.5 · Published 2026-04-15

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Payments component of Google Chrome for Android. This flaw could allow a remote attacker to execute malicious code on a user's device if the user is tricked into visiting a specifically crafted website and performing certain touch gestures. Such an attack could lead to the theft of sensitive information or unauthorized access to the device's functions.

Technical details

A use-after-free (UAF) vulnerability exists in the Payments component of Google Chrome on Android. The flaw is triggered when a remote attacker convinces a user to visit a malicious HTML page and perform specific UI gestures, leading to memory corruption. This vulnerability can be leveraged for remote code execution (RCE) within the context of the browser process. The issue was addressed in Google Chrome version 147.0.7727.101. The attack requires user interaction and specific conditions (high complexity) but can result in full compromise of confidentiality, integrity, and availability.

Affected products

  • Google Chrome prior to 147.0.7727.101

Timeline

  • 2026-04-02: other: Vulnerability reported by researcher pwn2addr
  • 2026-04-15: patched: Fixed in version 147.0.7727.101
  • 2026-04-15: disclosed: Public advisory published

References

Related threats