MEDIUM

CVE-2026-13282

Google Chrome 2026-06-25 CVSS v3.1
CVSS
6.8

Description

Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: High)

Summary dbcve.org

A use-after-free vulnerability exists in the Payments component of Google Chrome on Android before version 149.0.7827.201. A local attacker with physical access to the device can potentially exploit heap corruption by manipulating memory after it has been freed, which may allow arbitrary code execution or further memory corruption.

Mitigation

Update Google Chrome for Android to version 149.0.7827.201 or later to patch the vulnerability. Restrict physical access to sensitive devices as a defense-in-depth measure.

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

0.15%
Probability of exploitation in next 30 days
4.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE