CVE-2026-12013

8.8

Google · Chrome

A use-after-free vulnerability exists in the Media component of Google Chrome on Windows, potentially allowing remote code execution or system compromise.

Executive summary

A critical use-after-free vulnerability in Google Chrome on Windows requires immediate patching to prevent potential remote code execution and system compromise.

Vulnerability

This is a use-after-free vulnerability located within the Media component of Google Chrome. A remote, unauthenticated attacker could trigger this flaw to achieve remote code execution, cause a denial of service, bypass security restrictions, or disclose sensitive information.

Business impact

With a CVSS score of 8.8, this vulnerability poses a high risk to organizational security. Successful exploitation could lead to full system compromise, unauthorized data access, and significant disruption to business operations. Given the browser's role as a primary gateway to corporate resources, the potential for lateral movement within the network is substantial.

Remediation

Immediate Action: Update all Google Chrome instances on Windows to version 149.0.7827.114 or 149.0.7827.115 immediately.

Proactive Monitoring: Review endpoint logs for unexpected browser process crashes or unusual network traffic patterns originating from Chrome.

Compensating Controls: Deploy Web Application Firewalls (WAF) or endpoint protection solutions capable of detecting and blocking malicious scripts often used to trigger browser-based vulnerabilities.

Exploitation status

Public Exploit Available: false

Analyst recommendation

The severity of this flaw necessitates an immediate, organization-wide update to the patched version of Google Chrome. Security teams should prioritize this deployment to mitigate the significant risk of remote code execution and potential data breach.

More Google CVEs