CVE-2026-13283
published 2026-06-25CVE-2026-13283: Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific UI gestures…
PriorityP344high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
0.23%
13.6th percentile
Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 149.0.7827.201 | 149.0.7827.201 | |
| chrome | >= 149.0.7827.201 < 149.0.7827.201 | 149.0.7827.201 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2026-13281
vendor_chrome·2026-06-25
CVE-2026-13281 [HIGH] Stable Channel Update for Desktop: CVE-2026-13281
Stable Channel Update for Desktop
CVE-2026-13281: Integer overflow in Mojo. Reported by Google on 2026-05-14 [N/A][ 517522620 ] High CVE-2026-13282: Use after free in Payments
Reported by Google on 2026-05-28 [N/A][ 522561151 ] High CVE-2026-13283: Use after free in AdFilter
Severity: high
Red Hat
chromium-browser: chromium-browser: Use after free in AdFilter
vendor_redhat·2026-06-25·CVSS 7.5
CVE-2026-13283 [HIGH] CWE-825 chromium-browser: chromium-browser: Use after free in AdFilter
chromium-browser: chromium-browser: Use after free in AdFilter
Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
An use after free flaw was found in the AdFilter component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=522561151
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
GHSA
Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted
ghsa_unreviewed·2026-06-26
CVE-2026-13283 [HIGH] CWE-416 Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted
Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
VulDB
Google Chrome up to 149.0.7827.197 on Android AdFilter use after free (ID 522561 / EUVD-2026-39563)
vuldb·2026-06-26
CVE-2026-13283 [CRITICAL] Google Chrome up to 149.0.7827.197 on Android AdFilter use after free (ID 522561 / EUVD-2026-39563)
A vulnerability identified as critical has been detected in Google Chrome on Android. This affects an unknown part of the component AdFilter. The manipulation leads to use after free.
This vulnerability is documented as CVE-2026-13283. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-13283 chromium: chromium-browser: Use after free in AdFilter [epel-all]
bugzilla·2026-06-29·CVSS 7.5
CVE-2026-13283 [HIGH] CVE-2026-13283 chromium: chromium-browser: Use after free in AdFilter [epel-all]
CVE-2026-13283 chromium: chromium-browser: Use after free in AdFilter [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Discussion:
Fixed in chromium-149.0.7827.200
Bugzilla
CVE-2026-13283 chromium: chromium-browser: Use after free in AdFilter [fedora-all]
bugzilla·2026-06-29·CVSS 7.5
CVE-2026-13283 [HIGH] CVE-2026-13283 chromium: chromium-browser: Use after free in AdFilter [fedora-all]
CVE-2026-13283 chromium: chromium-browser: Use after free in AdFilter [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Discussion:
Fixed in chromium-149.0.7827.200
Bugzilla
CVE-2026-13283 chromium-browser: chromium-browser: Use after free in AdFilter
bugzilla·2026-06-25·CVSS 7.5
CVE-2026-13283 [HIGH] CVE-2026-13283 chromium-browser: chromium-browser: Use after free in AdFilter
CVE-2026-13283 chromium-browser: chromium-browser: Use after free in AdFilter
Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
2026-06-25
Published