Description
Use after free in Digital Credentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-06-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free bug in the Digital Credentials component of Google Chrome. When a specially crafted HTML page is rendered, the browser can corrupt heap memory, potentially allowing a remote attacker to execute arbitrary code. The flaw is classified as a memory corruption weakness (CWE‑416) and is marked as Critical by Chromium security. The impact is a loss of integrity and confidentiality for the user session, and could lead to full system compromise if exploited successfully.

Affected Systems

All Chrome installations running a version prior to 149.0.7827.155 are affected. The vulnerability applies to desktop operating systems where the Digital Credentials feature is enabled. Users on older releases or using earlier versions of Chrome should verify the installed version and consider upgrading if they have not done so already.

Risk and Exploitability

The EPSS score of less than 1% indicates that the probability of exploitation in the wild is low, and the vulnerability is not listed in CISA's KEV catalog. Nevertheless, the flaw is of high severity; if an attacker can serve the crafted page to a victim, the memory corruption could be leveraged to run code with the privileges of the Chrome process. The likely attack vector involves an HTTP(S) page containing the malicious content, making it a remote attack that requires the victim to load the page. While the current exploitation probability is low, mitigators should not rely on this – it remains a potentially critical vector that must be patched.

Generated by OpenCVE AI on June 17, 2026 at 17:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome version 149.0.7827.155 or later, which contains the fix for the use‑after‑free in Digital Credentials
  • Disable the Digital Credentials feature in Chrome settings or via policy if an immediate patch is not possible
  • Ensure that browsers are automatically updated to receive security patches as soon as they are released

Generated by OpenCVE AI on June 17, 2026 at 17:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 18 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 17 Jun 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 17 Jun 2026 05:15:00 +0000

Type Values Removed Values Added
Description Use after free in Digital Credentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-18T03:55:18.757Z

Reserved: 2026-06-16T19:38:23.945Z

Link: CVE-2026-12439

cve-icon Vulnrichment

Updated: 2026-06-17T12:54:23.133Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T18:00:04Z

Weaknesses