CVE-2026-12443: Critical Use after free in Web Authentication
Chromium: CVE-2026-12443 Use after free in Web Authentication
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 149.0.4022.80 - Upgrade
Upgrade
Google Chrome / Chromium (Web Authentication)to a version that resolves this vulnerability.Fixed in 149.0.7827.155
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-12443?
The severity of CVE-2026-12443 is rated as Critical.
How do I fix CVE-2026-12443?
To fix CVE-2026-12443, update Google Chrome to version 149.0.7827.155 or later.
What type of vulnerability is CVE-2026-12443?
CVE-2026-12443 is classified as a Use After Free vulnerability.
What can an attacker do with CVE-2026-12443?
An attacker can execute arbitrary code via a crafted HTML page using CVE-2026-12443.
In which software is CVE-2026-12443 found?
CVE-2026-12443 is found in Google Chrome versions prior to 149.0.7827.155.