PatchSiren cyber security CVE debrief
CVE-2026-12460 Google CVE debrief
CVE-2026-12460 is a High-severity vulnerability in Google Chrome, where insufficient policy enforcement in File System Access allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. This issue was addressed in Google Chrome version 149.0.7827.155. Users should update to the latest version to mitigate this risk. The vulnerability was publicly disclosed on June 17, 2026. The CVSS score for this vulnerability is 4.2, indicating a Medium severity level. Organizations using Google Chrome should prioritize updating to the latest version to prevent potential exploitation.
- Vendor
- Product
- Chrome
- CVSS
- MEDIUM 4.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-17
- Original CVE updated
- 2026-06-17
- Advisory published
- 2026-06-17
- Advisory updated
- 2026-06-17
Who should care
Users of Google Chrome prior to version 149.0.7827.155, IT administrators responsible for managing Google Chrome installations, and security teams monitoring for potential threats.
Technical summary
The vulnerability, CVE-2026-12460, is caused by insufficient policy enforcement in File System Access in Google Chrome. A remote attacker who has compromised the renderer process can exploit this vulnerability by providing a crafted PDF file, allowing them to bypass site isolation. This issue was resolved in Google Chrome version 149.0.7827.155. The Common Vulnerabilities and Exposures (CVE) score for this vulnerability is 4.2, with a CVSS vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N.
Defensive priority
High
Recommended defensive actions
- Update Google Chrome to version 149.0.7827.155 or later
- Ensure all users are running the latest version of Google Chrome
- Monitor for suspicious PDF files or unusual activity
- Implement additional security measures such as site isolation and sandboxing
- Regularly review and update browser extensions and plugins
- Consider implementing a vulnerability management program
- Review and update incident response plans to address potential exploitation
Evidence notes
This vulnerability was publicly disclosed on June 17, 2026, and was addressed in Google Chrome version 149.0.7827.155. The CVE record and NVD detail provide additional information on this vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-12460 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-12460
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-12460 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-12460
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://chromereleases.googleblog.com/2026/06/stable-channel-update-for-desktop_01750511403.html
[email protected] - Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://issues.chromium.org/issues/517484284
[email protected] - Permissions Required
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.