HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-12011Published Modified CNA Chrome

CVE-2026-12011: Use after free in WebMIDI in Google Chrome on Windows prior to 149

Use after free in WebMIDI in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
149.0.7827.115
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

Use-after-free vulnerability in the WebMIDI component of Google Chrome on Windows affects versions prior to 149.0.7827.115. The flaw is reachable over the network and requires no authentication, but does require a victim to visit a crafted HTML page, and exploiting it also requires the attacker to have already compromised the Chrome renderer process. Successful exploitation enables a full sandbox escape, giving the attacker high-impact read, write, and availability control outside the browser sandbox. A patched-image rebuild at version 149.0.7827.115 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle a Chrome or Chromium binary.

Available
Triage

HarborGuard scores this CVE at 8.3 HIGH (CVSS v3.1) and is capable of weighting that score against each environment's compliance policy to surface the finding to the appropriate team or queue inside each customer organization.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.115 is available on HarborGuard for any scanned image found to contain an affected version. For customers with auto-remediation enabled, HarborGuard can trigger a rebuild, run a regression test suite, and open a PR against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the crafted HTML page over the network, requiring the victim's browser to reach or be directed to attacker-controlled content.

  • AuthenticationNot required

    No credentials or account access are needed; the attack is launched against any unauthenticated user who visits the page.

  • Victim interactionRequired

    The victim must visit a crafted HTML page, making this a social-engineering or drive-by delivery scenario.

  • Attack complexityDetail

    Exploitation is rated high complexity because the attacker must first compromise the Chrome renderer process before the use-after-free can be leveraged for a sandbox escape.

Blast Radius

  • Attacker escapes the Chrome sandbox and executes arbitrary code in the context of the browser process on the host Windows system.
  • Confidential data accessible to the browser process, including stored credentials, cookies, and session tokens, is exposed to the attacker.
  • The attacker can write or modify files and system state accessible to the browser process user account.
  • The browser process and dependent services can be crashed or made unavailable.

How HarborGuard Handles This

Available on HarborGuard: images containing Google Chrome prior to 149.0.7827.115 are flagged automatically as affected versions are matched against the published advisory. A rebuilt image at the fixed version (149.0.7827.115) is available for affected environments. For customers who opt into auto-remediation, HarborGuard triggers a rebuild at the patched version, runs a regression test, and opens a PR against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled. Where compliance policy requires manual approval, the finding is routed to the designated inbox with full CVSS context and the fix version pre-populated. Given the sandbox-escape severity and the prerequisite of a compromised renderer, teams should also consider network-policy controls that restrict outbound browser process connections as a compensating control until the patched image is deployed.

See how HarborGuard automates this

Fix available

149.0.7827.115
Affected packages
  • Google / Chrome
    < 149.0.7827.115 (from 149.0.7827.115)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H