Google Chrome < 149.0.7827.155 Multiple Vulnerabilities

critical Nessus Plugin ID 321273

Synopsis

A web browser installed on the remote macOS host is affected by multiple vulnerabilities.

Description

The version of Google Chrome installed on the remote macOS host is prior to 149.0.7827.155. It is, therefore, affected by multiple vulnerabilities as referenced in the 2026_06_stable-channel-update-for-desktop_01750511403 advisory.

- Use after free in Extensions. (CVE-2026-12445, CVE-2026-12467)

- Use after free in WebShare. (CVE-2026-12437)

- Inappropriate implementation in WebView. (CVE-2026-12438, CVE-2026-12448)

- Use after free in Digital Credentials. (CVE-2026-12439)

- Use after free in DigitalCredentials. (CVE-2026-12440, CVE-2026-12451)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to Google Chrome version 149.0.7827.155 or later.

See Also

http://www.nessus.org/u?be44db35

https://crbug.com/516496659

https://crbug.com/516947912

https://crbug.com/519728275

https://crbug.com/519731619

https://crbug.com/520157118

https://crbug.com/521950423

https://crbug.com/522566295

https://crbug.com/513160088

https://crbug.com/513199795

https://crbug.com/513313107

https://crbug.com/513405023

https://crbug.com/513458233

https://crbug.com/513480539

https://crbug.com/514531776

https://crbug.com/514741076

https://crbug.com/515462244

https://crbug.com/516448843

https://crbug.com/516926968

https://crbug.com/517069848

https://crbug.com/517124587

https://crbug.com/517153117

https://crbug.com/517258337

https://crbug.com/517406035

https://crbug.com/517484284

https://crbug.com/517727318

https://crbug.com/517916024

https://crbug.com/518042749

https://crbug.com/519358344

https://crbug.com/520189702

https://crbug.com/520199394

https://crbug.com/520202726

https://crbug.com/521485244

https://crbug.com/521618871

Plugin Details

Severity: Critical

ID: 321273

File Name: macosx_google_chrome_149_0_7827_155.nasl

Version: 1.1

Type: Local

Agent: macosx

Published: 6/16/2026

Updated: 6/16/2026

Supported Sensors: Nessus Agent, Nessus

Risk Information

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-12467

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:google:chrome

Required KB Items: installed_sw/Google Chrome

Exploit Ease: No known exploits are available

Patch Publication Date: 6/16/2026

Vulnerability Publication Date: 6/16/2026

Reference Information

CVE: CVE-2026-12437, CVE-2026-12438, CVE-2026-12439, CVE-2026-12440, CVE-2026-12441, CVE-2026-12442, CVE-2026-12443, CVE-2026-12444, CVE-2026-12445, CVE-2026-12446, CVE-2026-12447, CVE-2026-12448, CVE-2026-12449, CVE-2026-12450, CVE-2026-12451, CVE-2026-12452, CVE-2026-12453, CVE-2026-12454, CVE-2026-12455, CVE-2026-12456, CVE-2026-12457, CVE-2026-12458, CVE-2026-12459, CVE-2026-12460, CVE-2026-12461, CVE-2026-12462, CVE-2026-12463, CVE-2026-12464, CVE-2026-12465, CVE-2026-12466, CVE-2026-12467, CVE-2026-12468, CVE-2026-12469