HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-12013Published Modified CNA Chrome

CVE-2026-12013: Use after free in Media in Google Chrome on Windows prior to 149

Use after free in Media in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
149.0.7827.115
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability exists in the Media component of Google Chrome on Windows in versions prior to 149.0.7827.115. The flaw is reachable over the network and requires no authentication, but the victim must visit a crafted HTML page that triggers the memory corruption. Successful exploitation gives an attacker full read, write, and crash capability over the affected process, enabling data theft, content tampering, or denial of service. A patched-image rebuild at version 149.0.7827.115 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle Chrome on Windows base layers.

Available
Triage

HarborGuard scores this issue at CVSS 8.8 (High) and weights it against each environment's compliance policy to determine urgency and routing. Findings are dispatched to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild pinned to Chrome 149.0.7827.115 becomes available on HarborGuard for any environment running an affected version. For customers with auto-remediation enabled, HarborGuard triggers the rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by luring the victim to a crafted HTML page, so the Chrome instance must be reachable from or browsing to an attacker-controlled origin.

  • AuthenticationNot required

    No account credentials or session tokens are needed; any unauthenticated remote attacker can serve the malicious page.

  • Victim interactionRequired

    The victim must navigate to or be redirected to the attacker's crafted HTML page, making this a social-engineering or drive-by delivery scenario.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and imposes no special timing, race-condition, or environment prerequisites on the attacker.

Blast Radius

  • An attacker gains read access to heap memory in the Chrome renderer process, exposing in-memory session tokens, form data, and page content.
  • Write primitives from the heap corruption allow the attacker to modify renderer state, tamper with displayed page content, or pivot to further exploitation.
  • The vulnerability can be used to crash the affected Chrome process entirely, causing denial of service for the active browsing session.
  • Depending on sandbox escape primitives available on the target system, heap corruption of this class can serve as a stepping stone to arbitrary code execution on the host.

How HarborGuard Handles This

Available on HarborGuard: detection fires within minutes of CVE publication for any customer image that ships Chrome on a Windows base layer, covering both registry-stored images and images built inline in CI pipelines. For customers with auto-remediation enabled, HarborGuard rebuilds the image at Chrome 149.0.7827.115, runs a regression test pass, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuilt image and a pre-populated pull request are staged and waiting for reviewer sign-off. Customers who cannot immediately redeploy should consider isolating affected Windows container workloads via network policy to restrict outbound browsing-context exposure until the patched image is rolled out.

See how HarborGuard automates this

Fix available

149.0.7827.115
Affected packages
  • Google / Chrome
    < 149.0.7827.115 (from 149.0.7827.115)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H