CVE-2026-13282
published 2026-06-25CVE-2026-13282: Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical…
PriorityP428medium6.8CVSS 3.1
AVPACLPRNUINSUCHIHAH
EPSS
0.16%
5.9th percentile
Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: High)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 149.0.7827.201 | 149.0.7827.201 | |
| chrome | >= 149.0.7827.201 < 149.0.7827.201 | 149.0.7827.201 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2026-13281
vendor_chrome·2026-06-25
CVE-2026-13281 [HIGH] Stable Channel Update for Desktop: CVE-2026-13281
Stable Channel Update for Desktop
CVE-2026-13281: Integer overflow in Mojo. Reported by Google on 2026-05-14 [N/A][ 517522620 ] High CVE-2026-13282: Use after free in Payments
Reported by Google on 2026-05-28 [N/A][ 522561151 ] High CVE-2026-13283: Use after free in AdFilter
Severity: high
Red Hat
chromium-browser: chromium-browser: Use after free in Payments
vendor_redhat·2026-06-25·CVSS 6.8
CVE-2026-13282 [MEDIUM] CWE-825 chromium-browser: chromium-browser: Use after free in Payments
chromium-browser: chromium-browser: Use after free in Payments
Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: High)
An use after free flaw was found in the Payments component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=517522620
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
GHSA
Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device.
ghsa_unreviewed·2026-06-26
CVE-2026-13282 [MEDIUM] CWE-416 Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device.
Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: High)
VulDB
Google Chrome up to 149.0.7827.197 on Android Payments use after free (ID 517522 / EUVD-2026-39584)
vuldb·2026-06-26
CVE-2026-13282 [CRITICAL] Google Chrome up to 149.0.7827.197 on Android Payments use after free (ID 517522 / EUVD-2026-39584)
A vulnerability classified as critical has been found in Google Chrome on Android. The affected element is an unknown function of the component Payments. Performing a manipulation results in use after free.
This vulnerability is known as CVE-2026-13282. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-13282 chromium: chromium-browser: Use after free in Payments [epel-all]
bugzilla·2026-06-29·CVSS 6.8
CVE-2026-13282 [MEDIUM] CVE-2026-13282 chromium: chromium-browser: Use after free in Payments [epel-all]
CVE-2026-13282 chromium: chromium-browser: Use after free in Payments [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: High)
Discussion:
Fixed in chromium-149.0.7827.200
Bugzilla
CVE-2026-13282 chromium: chromium-browser: Use after free in Payments [fedora-all]
bugzilla·2026-06-29·CVSS 6.8
CVE-2026-13282 [MEDIUM] CVE-2026-13282 chromium: chromium-browser: Use after free in Payments [fedora-all]
CVE-2026-13282 chromium: chromium-browser: Use after free in Payments [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: High)
Discussion:
Fixed in chromium-149.0.7827.200
Bugzilla
CVE-2026-13282 chromium-browser: chromium-browser: Use after free in Payments
bugzilla·2026-06-25·CVSS 6.8
CVE-2026-13282 [MEDIUM] CVE-2026-13282 chromium-browser: chromium-browser: Use after free in Payments
CVE-2026-13282 chromium-browser: chromium-browser: Use after free in Payments
Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: High)
2026-06-25
Published