# Google Chrome Patches Three Code-Execution Flaws

Published: 2026-06-26 · Severity: medium
Canonical: https://vorant.io/reports/1185143b-151a-5407-acbb-12288d471114/google-chrome-patches-three-code-execution-flaws

> Google patched three Chrome vulnerabilities that could allow arbitrary code execution, with no known active exploitation.

Google Chrome versions prior to 149.0.7827.200/201 contain three vulnerabilities that could allow arbitrary code execution in the context of the logged-on user: an integer overflow in Mojo (CVE-2026-13281), and use-after-free flaws in the Payments component (CVE-2026-13282) and AdFilter component (CVE-2026-13283). Successful exploitation could let an attacker install programs, manipulate or delete data, or create new accounts with full user rights, with impact scaled by the privileges of the logged-in user.

MS-ISAC reports no current evidence of in-the-wild exploitation. The advisory frames the risk via a drive-by compromise scenario, where a user visiting a malicious or compromised webpage could trigger exploitation. Organizations are advised to apply Google's updates promptly, enforce least-privilege principles, and deploy standard browser-hardening and exploit-mitigation controls.

## Mentioned in this report

- Vulnerabilities: CVE-2026-13281, CVE-2026-13282, CVE-2026-13283

Source reporting: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-063

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/1185143b-151a-5407-acbb-12288d471114/google-chrome-patches-three-code-execution-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
