Description
Use after free in Passwords in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
Published: 2026-06-17
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw in the password storage component of Google Chrome on Android. An attacker can trigger the flaw by delivering a specially crafted HTML page, causing arbitrary code execution with the privileges of the browser process. The weakness (CWE‑416) undermines the integrity and confidentiality of user data and allows a complete compromise of the device.

Affected Systems

Google Chrome for Android versions earlier than 149.0.7827.155 are affected. Users of the stable channel or any channel that has not yet received the 149.0.7827.155 update remain vulnerable.

Risk and Exploitability

The CVSS score of 8.8 reflects a high severity for remote exploitation. The EPSS score of less than 1% indicates a low probability of public exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. Still, the attack can be carried out remotely by a crafted web page, suggesting a broad potential impact if an attacker can lure a user to a malicious site.

Generated by OpenCVE AI on June 17, 2026 at 17:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 149.0.7827.155 or newer via the official update channel.
  • If an update cannot be applied immediately, block access to potentially malicious HTML content by configuring corporate web filters or using the browser's safe browsing controls.
  • For devices that cannot be updated, consider uninstalling Chrome or resetting the device to a factory state after backing up data.

Generated by OpenCVE AI on June 17, 2026 at 17:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 17 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 17 Jun 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 17 Jun 2026 05:15:00 +0000

Type Values Removed Values Added
Description Use after free in Passwords in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-17T12:57:49.543Z

Reserved: 2026-06-16T19:38:25.102Z

Link: CVE-2026-12442

cve-icon Vulnrichment

Updated: 2026-06-17T12:57:42.339Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T06:30:03Z

Weaknesses