MEDIUM
CVE-2026-13282
CVSS
6.8
Description
Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: High)
Summary dbcve.org
A use-after-free vulnerability exists in the Payments component of Google Chrome on Android before version 149.0.7827.201. A local attacker with physical access to the device can potentially exploit heap corruption by manipulating memory after it has been freed, which may allow arbitrary code execution or further memory corruption.
Mitigation
Update Google Chrome for Android to version 149.0.7827.201 or later to patch the vulnerability. Restrict physical access to sensitive devices as a defense-in-depth measure.
Weakness (CWE)
CWE-416
Use After Free
EPSS Score
0.15%
Probability of exploitation in next 30 days
4.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.