CVE-2026-13282Disclosure(google / android)

MEDIUMCVSS 6.8 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch google android systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security severity: High)

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-416

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • android
  • chrome

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-26); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
androidchrome

1 version affected across 2 products

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-06-25: 1Mentions · 2026-06-26: 2Mentions · 2026-06-28: 1Active Exploitation · 2026-06-26: 1Patch / Workaround · 2026-06-28: 1Technical Details · 2026-06-26: 106-2506-2606-28
Signal classification3 categories
Disclosure
250.0%
Active Exploitation
125.0%
Patch
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-251
Disclosure1
2026-06-262
Active Exploitation1Disclosure1
2026-06-281
Patch1
Full discourse4 posts
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Google、Chromeの高深刻度 脆弱性3件を修正 CVE-2026-13281、CVE-2026-13282、CVE-2026-13283 https://rocket-boys.co.jp/security-measures-lab/chrome-high-severity-cve-2026-13281-patch/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The article announces that Google has fixed three high‑severity Chrome CVEs (CVE‑2026‑13281, CVE‑2026‑13282, CVE‑2026‑13283) and links to a patch resource.

    01001133
    445 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-13282 Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security s... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-13282

    Post summary

    The text announces CVE-2026-13282 as a use‑after‑free vulnerability in Chrome Payments on Android that could cause heap corruption; it provides technical details but no PoC, exploit, patch, or evidence of active exploitation.

    00010136
    4.1K followersView on X
  • VulDB 🛡@vuldb
    Active Exploitation

    A lot of offensive activities were identified targeting Google Chrome (CVE-2026-13282) https://vuldb.com/vuln/373996/cti

    Post summary

    The statement indicates that CVE-2026-13282 in Google Chrome is currently being targeted by offensive actors, though no specific exploit code or patch information is provided.

    00000102
    2.2K followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    There is a new vulnerability with elevated criticality in Google Chrome (CVE-2026-13282) https://vuldb.com/vuln/373996

    Post summary

    The post announces a new high‑criticality vulnerability (CVE‑2026‑13282) in Google Chrome, providing a link to a vulnerability database but offering no further technical or mitigation details.

    00000112
    2.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
OSgoogleandroid---
Appgooglechrome---

Explore more