PatchSiren cyber security CVE debrief
CVE-2026-12460 Google CVE debrief
CVE-2026-12460 is a High-severity vulnerability in Google Chrome, where insufficient policy enforcement in File System Access allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. This issue was addressed in Google Chrome version 149.0.7827.155. Users should update to the latest version to mitigate this risk. The vulnerability was publicly disclosed on June 17, 2026. The CVSS score for this vulnerability is 4.2, indicating a Medium severity level. Organizations using Google Chrome should prioritize updating to the latest version to prevent potential exploitation.
- Vendor
- Product
- Chrome
- CVSS
- MEDIUM 4.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-17
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-17
Who should care
Users of Google Chrome prior to version 149.0.7827.155, IT administrators responsible for managing Google Chrome installations, and security teams monitoring for potential threats.
Technical summary
The vulnerability, CVE-2026-12460, is caused by insufficient policy enforcement in File System Access in Google Chrome. A remote attacker who has compromised the renderer process can exploit this vulnerability by providing a crafted PDF file, allowing them to bypass site isolation. This issue was resolved in Google Chrome version 149.0.7827.155. The Common Vulnerabilities and Exposures (CVE) score for this vulnerability is 4.2, with a CVSS vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N.
Defensive priority
High
Recommended defensive actions
- Update Google Chrome to version 149.0.7827.155 or later
- Ensure all users are running the latest version of Google Chrome
- Monitor for suspicious PDF files or unusual activity
- Implement additional security measures such as site isolation and sandboxing
- Regularly review and update browser extensions and plugins
- Consider implementing a vulnerability management program
- Review and update incident response plans to address potential exploitation
Evidence notes
This vulnerability was publicly disclosed on June 17, 2026, and was addressed in Google Chrome version 149.0.7827.155. The CVE record and NVD detail provide additional information on this vulnerability.
Official resources
-
CVE-2026-12460 CVE record
CVE.org
-
CVE-2026-12460 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
-
Source reference
[email protected] - Permissions Required
CVE-2026-12460 was publicly disclosed on June 17, 2026.