CVE-2026-12013: Use after free in Media in Google Chrome on Windows prior to 149
Use after free in Media in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 149.0.7827.115
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A use-after-free vulnerability exists in the Media component of Google Chrome on Windows in versions prior to 149.0.7827.115. The flaw is reachable over the network and requires no authentication, but the victim must visit a crafted HTML page that triggers the memory corruption. Successful exploitation gives an attacker full read, write, and crash capability over the affected process, enabling data theft, content tampering, or denial of service. A patched-image rebuild at version 149.0.7827.115 is available on HarborGuard for affected environments.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle Chrome on Windows base layers.
AvailableHarborGuard scores this issue at CVSS 8.8 (High) and weights it against each environment's compliance policy to determine urgency and routing. Findings are dispatched to the appropriate team inbox within each customer organization based on configured ownership rules.
AvailableA patched-image rebuild pinned to Chrome 149.0.7827.115 becomes available on HarborGuard for any environment running an affected version. For customers with auto-remediation enabled, HarborGuard triggers the rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network by luring the victim to a crafted HTML page, so the Chrome instance must be reachable from or browsing to an attacker-controlled origin.
- AuthenticationNot required
No account credentials or session tokens are needed; any unauthenticated remote attacker can serve the malicious page.
- Victim interactionRequired
The victim must navigate to or be redirected to the attacker's crafted HTML page, making this a social-engineering or drive-by delivery scenario.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and imposes no special timing, race-condition, or environment prerequisites on the attacker.
Blast Radius
- An attacker gains read access to heap memory in the Chrome renderer process, exposing in-memory session tokens, form data, and page content.
- Write primitives from the heap corruption allow the attacker to modify renderer state, tamper with displayed page content, or pivot to further exploitation.
- The vulnerability can be used to crash the affected Chrome process entirely, causing denial of service for the active browsing session.
- Depending on sandbox escape primitives available on the target system, heap corruption of this class can serve as a stepping stone to arbitrary code execution on the host.
How HarborGuard Handles This
Available on HarborGuard: detection fires within minutes of CVE publication for any customer image that ships Chrome on a Windows base layer, covering both registry-stored images and images built inline in CI pipelines. For customers with auto-remediation enabled, HarborGuard rebuilds the image at Chrome 149.0.7827.115, runs a regression test pass, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuilt image and a pre-populated pull request are staged and waiting for reviewer sign-off. Customers who cannot immediately redeploy should consider isolating affected Windows container workloads via network policy to restrict outbound browsing-context exposure until the patched image is rolled out.
Fix available
- Google / Chrome< 149.0.7827.115 (from 149.0.7827.115)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H