HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-12018Published Modified CNA Chrome

CVE-2026-12018: Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149

Inappropriate implementation in Mojo in Google Chrome on Windows prior to 149.0.7827.115 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security severity: High)

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
149.0.7827.115
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An inappropriate implementation flaw in Mojo, the inter-process communication layer of Google Chrome on Windows, allows a local attacker to escalate privileges to the operating system level by convincing a user to open a malicious file. The CVSS vector reflects a network-delivered attack requiring user interaction but no authentication, with high impact across confidentiality, integrity, and availability. Successful exploitation gives the attacker elevated OS privileges, enabling full control over the affected host. A patched-image rebuild at version 149.0.7827.115 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle Chrome or Chromium on Windows base layers.

Available
Triage

HarborGuard scores this finding at CVSS 8.8 (High) and is capable of applying per-environment compliance policy weighting to adjust priority, then routing the alert to the appropriate team inbox within each customer organization.

Available
Patch

A patched-image rebuild pinned to Chrome 149.0.7827.115 becomes available through HarborGuard as soon as the upstream fix is confirmed. For customers who opt into auto-remediation, HarborGuard runs the rebuild, executes a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the malicious file over the network, requiring the target service or user to be reachable from the attacker's position.

  • AuthenticationNot required

    No account or credentials are needed; the attack can be launched by any unauthenticated party who can deliver a file to the target.

  • Victim interactionRequired

    The target user must open or interact with the attacker-supplied malicious file, making social engineering the primary delivery mechanism.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other hard-to-control environmental factors.

Blast Radius

  • A successful attacker gains OS-level elevated privileges on the affected Windows host, bypassing the Chrome sandbox boundary.
  • With elevated privileges, the attacker can read any files, credentials, or secrets accessible to higher-privileged processes on the system.
  • The attacker can write to or modify protected system files, installed software, and persisted data on the host.
  • The attacker can terminate processes, install persistent malware, or render the host inoperable, causing full service disruption.

How HarborGuard Handles This

Available on HarborGuard: detection fires within minutes of CVE publication for any image found to bundle an affected Chrome or Chromium version on a Windows base layer, covering both upstream and customer-built images. Where compliance policy permits auto-remediation, HarborGuard rebuilds the image at the patched version (149.0.7827.115), runs a regression test, and opens a pull request against affected workloads; for high-severity issues, the median time from CVE publication to a merged patch PR is around 90 minutes in environments with auto-remediation enabled. For teams that manage remediation manually, HarborGuard surfaces the affected image digests, the specific Chrome component version, and the recommended fix version directly in the finding detail so engineers can act without additional research.

See how HarborGuard automates this

Fix available

149.0.7827.115
Affected packages
  • Google / Chrome
    < 149.0.7827.115 (from 149.0.7827.115)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H