VORANT. Threat Intelligence Sign in Get the full feed

Google Chrome Patches Three Code-Execution Flaws

medium vulnerability

Google patched three Chrome vulnerabilities that could allow arbitrary code execution, with no known active exploitation.

Google Chrome versions prior to 149.0.7827.200/201 contain three vulnerabilities that could allow arbitrary code execution in the context of the logged-on user: an integer overflow in Mojo (CVE-2026-13281), and use-after-free flaws in the Payments component (CVE-2026-13282) and AdFilter component (CVE-2026-13283). Successful exploitation could let an attacker install programs, manipulate or delete data, or create new accounts with full user rights, with impact scaled by the privileges of the logged-in user.

MS-ISAC reports no current evidence of in-the-wild exploitation. The advisory frames the risk via a drive-by compromise scenario, where a user visiting a malicious or compromised webpage could trigger exploitation. Organizations are advised to apply Google's updates promptly, enforce least-privilege principles, and deploy standard browser-hardening and exploit-mitigation controls.

Mentioned in this report

Vulnerabilities CVE-2026-13281CVE-2026-13282CVE-2026-13283

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-063

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free