CVE-2026-12443Patch(apple / chrome)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apple chrome systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-06-17); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-06-17: 1Mentions · 2026-06-19: 1Mentions · 2026-07-10: 1Patch / Workaround · 2026-06-17: 1Patch / Workaround · 2026-07-10: 106-1706-1907-10
Signal classification2 categories
Patch
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-171
Patch1
2026-06-191
General1
2026-07-101
Patch1
Full discourse3 posts
  • kawn@kawn2020
    Patch

    #securityupdate #chromeos Google が LTS-144 バージョンとして ChromeOS 144.0.7559.257 (Platform Version: 16503.90.0) をリリース. Critical 2 件 ・CVE-2026-8514 ・CVE-2026-12443 および High 8 件の脆弱性に対処. https://x.com/kawn2020/status/2075424859585458409

    Post summary

    Google disclosed a new ChromeOS LTS-144 update that patches two critical CVEs, CVE-2026-8514 and CVE-2026-12443, along with eight high‑severity vulnerabilities.

    0001065
    90 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Google、Chromeの脆弱性 33件を修正(CVE-2026-12437,CVE-2026-12443)他 https://rocket-boys.co.jp/security-measures-lab/google-chrome-33-cve-2026-12437-12443/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The post reports that Google Chrome has released patches for 33 vulnerabilities, including CVE-2026-12437 and CVE-2026-12443.

    00001148
    431 followersView on X
  • WindowsForum@windowsforum
    General

    🪟 CVE-2026-12443 is the reminder: your “Edge security” is basically “how fast Chromium got patched.” Supply-chain bugs don’t care what logo you click—only versions. https://windowsforum.com/threads/cve-2026-12443-and-edge-chromium-webauth-uaf-fix-how-to-verify-your-version.428189/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #MicrosoftEdge #WindowsSecurityUpdates #Cve202612443 #ChromiumWebAuthentication https://t.co/xNabqBD0u7

    Post summary

    The post emphasizes the importance of keeping Microsoft Edge’s Chromium engine up‑to‑date for CVE‑2026‑12443, but offers no technical specifics, exploit code, or remediation guidance.

    0000027
    1.2K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more