HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-12008Published Modified CNA Chrome

CVE-2026-12008: Use after free in DigitalCredentials in Google Chrome prior to 149

Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
149.0.7827.115
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability in the DigitalCredentials component of Google Chrome (versions prior to 149.0.7827.115) allows a remote attacker who has already compromised the Chrome renderer process to escape the browser sandbox via a crafted HTML page. The attack is reachable over the network but requires the victim to visit a malicious page, and successful exploitation gives the attacker high-confidence code execution, data access, and the ability to tamper with or crash the host beyond the browser sandbox. A patched-image rebuild at version 149.0.7827.115 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-12008 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that bundle a Chromium or Chrome runtime.

Available
Triage

HarborGuard scores this CVE at CVSS 8.3 (HIGH) and weights it against each environment's per-org compliance policy before routing findings to the appropriate team inbox. Where a policy treats sandbox-escape vulnerabilities as critical-priority, the triage engine escalates accordingly.

Available
Patch

A patched-image rebuild pinned to Chrome 149.0.7827.115 is available on HarborGuard for any environment found to be running an affected version. For customers who opt into auto-remediation, HarborGuard triggers a rebuilt image, runs a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the crafted HTML page over the network, so the target Chrome instance must be reachable or directed to an attacker-controlled URL.

  • AuthenticationNot required

    No account or credential is needed; any user who browses to the malicious page can be targeted.

  • Victim interactionRequired

    The victim must visit the attacker-crafted HTML page, making this a social-engineering or drive-by browsing vector.

  • Attack complexityDetail

    Attack complexity is rated High, meaning the attacker must first compromise the Chrome renderer process before the use-after-free can be weaponised for a sandbox escape, introducing a prerequisite environmental condition.

Blast Radius

  • An attacker escaping the Chrome sandbox gains code execution in the context of the browser process on the host, bypassing the isolation boundary meant to contain renderer-level compromise.
  • Confidentiality impact is high: the attacker reads data accessible to the browser process, including stored credentials, cookies, and session tokens held in the browser profile.
  • Integrity impact is high: the attacker modifies files, browser state, or other data accessible to the Chrome process on the host.
  • Availability impact is high: the attacker can terminate or crash the browser process and any dependent services running under the same user context.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-12008 is active against all scanned images the moment the CVE enters upstream feeds, with no manual intervention required. For environments running Chrome prior to 149.0.7827.115, a rebuilt image at the fixed version is available immediately. For customers who have auto-remediation enabled, HarborGuard performs a full rebuild at 149.0.7827.115, runs a regression test run against the new image, and opens a pull request against affected workloads; for high-severity issues the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy does not permit auto-remediation, the finding is routed to the configured team inbox with full CVSS context and the fix version clearly indicated so the upgrade can be actioned manually.

See how HarborGuard automates this

Fix available

149.0.7827.115
Affected packages
  • Google / Chrome
    < 149.0.7827.115 (from 149.0.7827.115)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H