Google Chrome Patches Three Code-Execution Flaws
Google patched three Chrome vulnerabilities that could allow arbitrary code execution, with no known active exploitation.
Google Chrome versions prior to 149.0.7827.200/201 contain three vulnerabilities that could allow arbitrary code execution in the context of the logged-on user: an integer overflow in Mojo (CVE-2026-13281), and use-after-free flaws in the Payments component (CVE-2026-13282) and AdFilter component (CVE-2026-13283). Successful exploitation could let an attacker install programs, manipulate or delete data, or create new accounts with full user rights, with impact scaled by the privileges of the logged-in user.
MS-ISAC reports no current evidence of in-the-wild exploitation. The advisory frames the risk via a drive-by compromise scenario, where a user visiting a malicious or compromised webpage could trigger exploitation. Organizations are advised to apply Google's updates promptly, enforce least-privilege principles, and deploy standard browser-hardening and exploit-mitigation controls.
Mentioned in this report
Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-063
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free