Description
Use after free in Tab Strip in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A use-after-free flaw in Chrome’s Tab Strip module allows a crafted HTML page to trigger heap corruption. The vulnerability can be triggered when a user performs specific UI gestures, potentially enabling a malicious actor to execute arbitrary code in the browser’s process. The weakness is identified as a classic memory corruption issue (CWE‑416).

Affected Systems

Google Chrome browsers before version 149.0.7827.155 on desktop are affected. Users who have not upgraded to the latest stable channel release are at risk.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, but the EPSS score of less than 1% shows the exploitation likelihood is very low. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote, through a malicious web page that a user must open and interact with, and it requires the user to perform certain UI gestures to trigger the heap corruption.

Generated by OpenCVE AI on June 17, 2026 at 17:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 149.0.7827.155 or later.
  • Run Chrome using the principle of least privilege, avoiding administrative privileges for web browsing.
  • Enable Chrome’s built‑in safe‑browsing and exploit‑protection features to block malicious pages.

Generated by OpenCVE AI on June 17, 2026 at 17:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 17 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 17 Jun 2026 07:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 17 Jun 2026 05:15:00 +0000

Type Values Removed Values Added
Description Use after free in Tab Strip in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-17T13:10:21.883Z

Reserved: 2026-06-16T19:38:29.710Z

Link: CVE-2026-12455

cve-icon Vulnrichment

Updated: 2026-06-17T13:10:18.762Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-17T06:45:03Z

Weaknesses