CVE-2026-12449
published 2026-06-17CVE-2026-12449: Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-level privilege escalation via a…
high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.11%
1.5th percentile
Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | >= 149.0.7827.155 < 149.0.7827.155 | 149.0.7827.155 | |
| chrome_desktop | — | — |
CVSS provenance
cvelistv5v3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
chromium-browser: chromium-browser: Use after free in Chromoting
vendor_redhat·2026-06-17·CVSS 8.8
CVE-2026-12449 [HIGH] CWE-825 chromium-browser: chromium-browser: Use after free in Chromoting
chromium-browser: chromium-browser: Use after free in Chromoting
Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
An use after free flaw was found in the Chromoting component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=513480539
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Chrome
Stable Channel Update for Desktop: CVE-2026-12449
vendor_chrome·2026-06-16
CVE-2026-12449 [HIGH] Stable Channel Update for Desktop: CVE-2026-12449
Stable Channel Update for Desktop
CVE-2026-12449: Use after free in Chromoting. Reported by Google on 2026-05-15 [N/A][ 514531776 ] High CVE-2026-12450: Inappropriate implementation in Media
Reported by Zhixin Tu on 2026-05-19 [N/A][ 514741076 ] High CVE-2026-12451: Use after free in DigitalCredentials
Severity: high
CVEList
CVE-2026-12449: Use after free in Chromoting in Google Chrome on Windows prior to 149
cvelistv5·2026-06-17·CVSS 7.8
CVE-2026-12449 [HIGH] CWE-416 CVE-2026-12449: Use after free in Chromoting in Google Chrome on Windows prior to 149
Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
GHSA
Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-level privilege escalation via a malicious file.
ghsa_unreviewed·2026-06-17
CVE-2026-12449 [HIGH] CWE-416 Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-level privilege escalation via a malicious file.
Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-12437 CVE-2026-12438 CVE-2026-12439 CVE-2026-12440 CVE-2026-12441 CVE-2026-12442 CVE-2026-12443 CVE-2026-12444 CVE-2026-12445 CVE-2026-12446 CVE-2026-12447 CVE-2026-12448 CVE-2026-12449 CVE-2
bugzilla·2026-06-19
CVE-2026-12437 [HIGH] CVE-2026-12437 CVE-2026-12438 CVE-2026-12439 CVE-2026-12440 CVE-2026-12441 CVE-2026-12442 CVE-2026-12443 CVE-2026-12444 CVE-2026-12445 CVE-2026-12446 CVE-2026-12447 CVE-2026-12448 CVE-2026-12449 CVE-2
CVE-2026-12437 CVE-2026-12438 CVE-2026-12439 CVE-2026-12440 CVE-2026-12441 CVE-2026-12442 CVE-2026-12443 CVE-2026-12444 CVE-2026-12445 CVE-2026-12446 CVE-2026-12447 CVE-2026-12448 CVE-2026-12449 CVE-2026-12450 ... chromium: various flaws [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-EPEL-2026-ad8f61e943 (chromium-149.0.7827.155-1.el10_2) has been submitted as an update to Fedora EPEL 10.2.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-ad8f61e943
---
FEDORA-EPEL-2026-0c2688537b (chromium-149.0.7827.155-1.el9) has been submitted as an update to Fedora EPEL 9.
https://bodh
Bugzilla
CVE-2026-12437 CVE-2026-12438 CVE-2026-12439 CVE-2026-12440 CVE-2026-12441 CVE-2026-12442 CVE-2026-12443 CVE-2026-12444 CVE-2026-12445 CVE-2026-12446 CVE-2026-12447 CVE-2026-12448 CVE-2026-12449 CVE-2
bugzilla·2026-06-19
CVE-2026-12437 [HIGH] CVE-2026-12437 CVE-2026-12438 CVE-2026-12439 CVE-2026-12440 CVE-2026-12441 CVE-2026-12442 CVE-2026-12443 CVE-2026-12444 CVE-2026-12445 CVE-2026-12446 CVE-2026-12447 CVE-2026-12448 CVE-2026-12449 CVE-2
CVE-2026-12437 CVE-2026-12438 CVE-2026-12439 CVE-2026-12440 CVE-2026-12441 CVE-2026-12442 CVE-2026-12443 CVE-2026-12444 CVE-2026-12445 CVE-2026-12446 CVE-2026-12447 CVE-2026-12448 CVE-2026-12449 CVE-2026-12450 ... chromium: various flaws [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-f9a0af40b2 (chromium-149.0.7827.155-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-f9a0af40b2
Bugzilla
CVE-2026-12449 chromium-browser: chromium-browser: Use after free in Chromoting
bugzilla·2026-06-17
CVE-2026-12449 [HIGH] CVE-2026-12449 chromium-browser: chromium-browser: Use after free in Chromoting
CVE-2026-12449 chromium-browser: chromium-browser: Use after free in Chromoting
Use after free in Chromoting in Google Chrome on Windows prior to 149.0.7827.155 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)
Wiz
CVE-2025-12449 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2025-12449 [MEDIUM] CVE-2025-12449 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-12449 :
WordPress vulnerability analysis and mitigation
The aBlocks – WordPress Gutenberg Blocks plugin for WordPress is vulnerable to unauthorized modification of data and disclosure of sensitive information due to missing capability checks on multiple AJAX actions in all versions up to, and including, 2.4.0. This makes it possible for authenticated attackers, with subscriber level access and above, to read plugin settings including block visibility, maintenance mode configuration, and third-party email marketing API keys, as well as read sensitive configuration data including API keys for email marketing services.
Source : NVD
## 5.4
Score
Published January 7, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
WordPress
Has Public Exploit No
Has CISA KEV E
2026-06-17
Published