PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-12460 Google CVE debrief

CVE-2026-12460 is a High-severity vulnerability in Google Chrome, where insufficient policy enforcement in File System Access allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. This issue was addressed in Google Chrome version 149.0.7827.155. Users should update to the latest version to mitigate this risk. The vulnerability was publicly disclosed on June 17, 2026. The CVSS score for this vulnerability is 4.2, indicating a Medium severity level. Organizations using Google Chrome should prioritize updating to the latest version to prevent potential exploitation.

Vendor
Google
Product
Chrome
CVSS
MEDIUM 4.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-17
Original CVE updated
2026-06-17
Advisory published
2026-06-17
Advisory updated
2026-06-17

Who should care

Users of Google Chrome prior to version 149.0.7827.155, IT administrators responsible for managing Google Chrome installations, and security teams monitoring for potential threats.

Technical summary

The vulnerability, CVE-2026-12460, is caused by insufficient policy enforcement in File System Access in Google Chrome. A remote attacker who has compromised the renderer process can exploit this vulnerability by providing a crafted PDF file, allowing them to bypass site isolation. This issue was resolved in Google Chrome version 149.0.7827.155. The Common Vulnerabilities and Exposures (CVE) score for this vulnerability is 4.2, with a CVSS vector of CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N.

Defensive priority

High

Recommended defensive actions

  • Update Google Chrome to version 149.0.7827.155 or later
  • Ensure all users are running the latest version of Google Chrome
  • Monitor for suspicious PDF files or unusual activity
  • Implement additional security measures such as site isolation and sandboxing
  • Regularly review and update browser extensions and plugins
  • Consider implementing a vulnerability management program
  • Review and update incident response plans to address potential exploitation

Evidence notes

This vulnerability was publicly disclosed on June 17, 2026, and was addressed in Google Chrome version 149.0.7827.155. The CVE record and NVD detail provide additional information on this vulnerability.

Official resources

CVE-2026-12460 was publicly disclosed on June 17, 2026.