Description
Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-25
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a use-after-free error in the AdFilter component of Google Chrome on Android. A carefully crafted HTML page can be delivered to a user who engages in specific UI gestures, causing Chrome to execute arbitrary code. The flaw falls under CWE-416 and enables an attacker to run code with the privileges of the Chrome process, potentially compromising all data and processes accessible to the user.

Affected Systems

Google Chrome for Android, stable channel versions earlier than 149.0.7827.201, are susceptible. The issue is confined to the Android platform and affects installations of Chrome that have not been updated to the mentioned version.

Risk and Exploitability

The vulnerability has a High Chromium security severity rating and, due to its reliance on a crafted web page and specific user interactions, its exploitation requires an attacker to lure a user to malicious content. While no EPSS score is currently available and the vulnerability is not listed in CISA KEV, the potential for arbitrary code execution makes it a high‑risk condition. Effective exploitation would likely involve a phishing site or malicious advertisement that triggers the required UI gestures.

Generated by OpenCVE AI on June 25, 2026 at 23:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 149.0.7827.201 or later on Android
  • Ensure your Android device is running the latest OS build to receive bundled security patches
  • Avoid interacting with suspicious web content that may trigger the exploit until a patch is applied

Generated by OpenCVE AI on June 25, 2026 at 23:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 26 Jun 2026 00:15:00 +0000

Type Values Removed Values Added
Title AdFilter Use-after-Free Allows Remote Code Execution in Chrome for Android

Thu, 25 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Description Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-416
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-25T21:51:34.243Z

Reserved: 2026-06-24T21:53:14.107Z

Link: CVE-2026-13283

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-26T00:00:14Z

Weaknesses