CVE-2026-12008: Use after free in DigitalCredentials in Google Chrome prior to 149
Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 149.0.7827.115
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A use-after-free vulnerability in the DigitalCredentials component of Google Chrome (versions prior to 149.0.7827.115) allows a remote attacker who has already compromised the Chrome renderer process to escape the browser sandbox via a crafted HTML page. The attack is reachable over the network but requires the victim to visit a malicious page, and successful exploitation gives the attacker high-confidence code execution, data access, and the ability to tamper with or crash the host beyond the browser sandbox. A patched-image rebuild at version 149.0.7827.115 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection of CVE-2026-12008 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that bundle a Chromium or Chrome runtime.
AvailableHarborGuard scores this CVE at CVSS 8.3 (HIGH) and weights it against each environment's per-org compliance policy before routing findings to the appropriate team inbox. Where a policy treats sandbox-escape vulnerabilities as critical-priority, the triage engine escalates accordingly.
AvailableA patched-image rebuild pinned to Chrome 149.0.7827.115 is available on HarborGuard for any environment found to be running an affected version. For customers who opt into auto-remediation, HarborGuard triggers a rebuilt image, runs a regression test suite, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the crafted HTML page over the network, so the target Chrome instance must be reachable or directed to an attacker-controlled URL.
- AuthenticationNot required
No account or credential is needed; any user who browses to the malicious page can be targeted.
- Victim interactionRequired
The victim must visit the attacker-crafted HTML page, making this a social-engineering or drive-by browsing vector.
- Attack complexityDetail
Attack complexity is rated High, meaning the attacker must first compromise the Chrome renderer process before the use-after-free can be weaponised for a sandbox escape, introducing a prerequisite environmental condition.
Blast Radius
- An attacker escaping the Chrome sandbox gains code execution in the context of the browser process on the host, bypassing the isolation boundary meant to contain renderer-level compromise.
- Confidentiality impact is high: the attacker reads data accessible to the browser process, including stored credentials, cookies, and session tokens held in the browser profile.
- Integrity impact is high: the attacker modifies files, browser state, or other data accessible to the Chrome process on the host.
- Availability impact is high: the attacker can terminate or crash the browser process and any dependent services running under the same user context.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-12008 is active against all scanned images the moment the CVE enters upstream feeds, with no manual intervention required. For environments running Chrome prior to 149.0.7827.115, a rebuilt image at the fixed version is available immediately. For customers who have auto-remediation enabled, HarborGuard performs a full rebuild at 149.0.7827.115, runs a regression test run against the new image, and opens a pull request against affected workloads; for high-severity issues the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy does not permit auto-remediation, the finding is routed to the configured team inbox with full CVSS context and the fix version clearly indicated so the upgrade can be actioned manually.
Fix available
- Google / Chrome< 149.0.7827.115 (from 149.0.7827.115)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H