Google Chrome 149 Multiple Memory-Corruption Vulnerabilities Enable Arbitrary Code Execution (CVE-2026-12437 through CVE-2026-12469) — Threadlinqs Intelligence
As of 2026-06-20, Google Chrome 149 Multiple Memory-Corruption Vulnerabilities Enable Arbitrary Code Execution (CVE-2026-12437 through CVE-2026-12469) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 18 indicators of compromise.
Threat ID: TL-2026-0886 · Severity: CRITICAL · CVSS: 9.8 · Status: PATCHED · Category: VULNERABILITY
Google shipped Chrome Stable 149.0.7827.155/.156 (Windows/macOS) and 149.0.7827.155 (Linux) on 2026-06-17 with 33 security fixes, including 7 Critical use-after-free / inappropriate-implementation
On June 17, 2026, Google released a Chrome Stable channel update for desktop, advancing the Stable channel to 149.0.7827.155/.156 for Windows and macOS and 149.0.7827.155 for Linux. The release bundles 33 security fixes, with 7 rated Critical and 26 rated High. The dominant defect class is use-after-free (CWE-416), the most reliable primitive for browser remote code execution because a freed renderer object can be reclaimed by attacker-controlled heap data and then dereferenced to gain control of execution.
The 7 Critical vulnerabilities span privacy- and credential-sensitive surfaces: CVE-2026-12437 (use-after-free in WebShare), CVE-2026-12438 (inappropriate implementation in WebView), CVE-2026-12439 and CVE-2026-12440 (use-after-free in Digital Credentials), CVE-2026-12441 (use-after-free in File Input), CVE-2026-12442 (use-after-free in Passwords), and CVE-2026-12443 (use-after-free in Web Authentication). All seven were found internally by Google between 2026-05-25 and 2026-06-11 using its memory-safety tooling. The cluster touching Digital Credentials, Passwords, and Web Authentication is notable because successful exploitation of those components risks exposure of stored credentials, passkeys/WebAuthn assertions, and verifiable digital identity material in addition to renderer code execution.
The 26 High-severity issues affect a broad set of components including Chromoting, Extensions, WebRTC, WebView, Media, Downloads, Browser, Input, Safe Browsing, Tab Strip, Serial, File System Access, Views, Metrics, Updater, and GPU. Confirmed examples include CVE-2026-12444 (out-of-bounds read in Chromoting), CVE-2026-12445 and CVE-2026-12467 (use-after-free in Extensions), CVE-2026-12447, CVE-2026-12461, and CVE-2026-12466 (heap buffer overflow / out-of-bounds read in WebRTC), CVE-2026-12448 (inappropriate implementation in WebView), and CVE-2026-12451 (use-after-free in Digital Credentials). The WebRTC defects can be reached via crafted audio/video or signaling traffic, broadening the attack surface beyond a simple page load.
The practical exploitation model is a classic drive-by: an attacker hosts or compromises a web page containing a malicious script that triggers one of the memory-corruption bugs when the victim navigates to it, with no further user interaction required. A renderer-level memory-corruption primitive is typically chained with a sandbox-escape bug for full system compromise; this update hardens both renderer surfaces (WebShare, File Input, WebRTC, Extensions) and higher-privilege surfaces (Browser, Updater, GPU). Google has restricted access to detailed bug entries and links until the majority of users are updated, a standard practice to limit n-day exploitation during the gradual rollout. Tenable scored the bundle at CVSS v3 9.8 / CVSS v2 10.0 and reports no known public exploits at time of disclosure; no confirmed in-the-wild exploitation is stated in any source. Users and fleet managers should force-update Chrome immediately rather than waiting for the staged rollout.
Weaknesses (CWE)
CWE-416, CWE-122, CWE-125, CWE-787, CWE-362, CWE-457, CWE-451, CWE-20, CWE-863
Target sectors: all sectors, government, financial, healthcare, technology, education
Target regions: Global
Detections & IOCs
As of 2026-07-27, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 18 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-12437, CVE-2026-12438, CVE-2026-12439, CVE-2026-12440, CVE-2026-12441, CVE-2026-12442, CVE-2026-12443, CVE-2026-12444, CVE-2026-12445, CVE-2026-12446, T1189, T1203, T1059, T1068, T1211, T1212, T1555, T1539, T1185, T1005