PatchSiren cyber security CVE debrief
CVE-2026-12448 Google CVE debrief
CVE-2026-12448 is a High-severity vulnerability in Google Chrome's WebView on Android, allowing remote attackers to escalate privileges via a crafted HTML page. This issue was addressed in Chrome version 149.0.7827.155. Organizations should prioritize updating Chrome to the latest version to mitigate this vulnerability. The CVSS score for this vulnerability is 8.8, indicating a high level of severity. This vulnerability was publicly disclosed on June 17, 2026, and the CVE record was last modified on June 18, 2026.
- Vendor
- Product
- Chrome
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-18
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-18
Who should care
This vulnerability affects users of Google Chrome on Android. Organizations and individuals using Chrome on Android should update to the latest version to mitigate this vulnerability. Additionally, security teams and IT administrators responsible for managing Chrome deployments should be aware of this issue and take necessary actions to protect their environments.
Technical summary
The vulnerability is caused by an inappropriate implementation in WebView in Google Chrome on Android prior to version 149.0.7827.155. This allows a remote attacker to perform privilege escalation via a crafted HTML page. The CVSS vector for this vulnerability is CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating a high level of severity. The weakness associated with this vulnerability is CWE-269.
Defensive priority
High
Recommended defensive actions
- Update Google Chrome on Android to version 149.0.7827.155 or later
- Ensure that Chrome is configured to automatically update to the latest version
- Monitor Chrome deployments for any signs of exploitation
- Implement additional security measures, such as network segmentation and access controls, to limit the impact of a potential exploit
- Conduct regular security audits and vulnerability assessments to identify and address potential vulnerabilities
- Provide training and awareness programs for users on safe browsing practices and the importance of keeping software up to date
Evidence notes
The information provided is based on the CVE record and NVD details. The CVE record was publicly disclosed on June 17, 2026, and the CVE record was last modified on June 18, 2026. The vendor, Google, has provided references to additional information, including a stable channel update for desktop and an issue tracker entry.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-12448 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-12448
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-12448 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12448
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01750511403.html
-
Source reference
Unverified legacy reference
URL: https://issues.chromium.org/issues/513458233
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.