HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-12020Published Modified CNA Chrome

CVE-2026-12020: Use after free in Autofill in Google Chrome on Mac prior to 149

Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
149.0.7827.115
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability exists in the Autofill component of Google Chrome on macOS in versions prior to 149.0.7827.115. The flaw is reachable over the network and requires no authentication, but does require a user to visit a crafted HTML page. Successful exploitation corrupts heap memory, giving an attacker the ability to read sensitive data, tamper with application state, or execute arbitrary code within the browser process. A patched-image rebuild at version 149.0.7827.115 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-12020 is available across every HarborGuard environment; the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle Chrome on macOS base layers.

Available
Triage

HarborGuard scores this CVE at 8.8 HIGH using the CVSS v3.1 vector and is capable of weighting that score against each customer environment's compliance policy, then routing the finding to the appropriate team inbox within each organization.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.115 is available on HarborGuard for any environment running an affected version. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs regression tests, and opens a pull request against affected workloads automatically; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing the target to a crafted HTML page hosted remotely.

  • AuthenticationNot required

    No account or credential of any privilege level is needed to deliver the malicious page.

  • Victim interactionRequired

    The target user must visit the attacker-controlled HTML page, meaning the attack depends on a social-engineering or drive-by delivery step.

  • Attack complexityDetail

    Attack complexity is low; the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental preconditions.

Blast Radius

  • A successful attacker reads heap memory contents from the Chrome process, which may include stored autofill data such as addresses, payment card numbers, and form credentials.
  • The attacker modifies heap state within the browser process, enabling tampering with page content, session data, or in-process application logic.
  • Heap corruption of this class opens a path to arbitrary code execution within the Chrome renderer or browser process on the affected Mac host.
  • The Chrome process itself can be crashed, disrupting browser availability for the affected user.

How HarborGuard Handles This

Available on HarborGuard: any container image that packages Google Chrome on a macOS base layer at a version below 149.0.7827.115 is flagged when scanned. Where compliance policy permits, HarborGuard can automatically rebuild the image at the fixed version (149.0.7827.115), execute the configured regression test suite against the rebuilt image, and open a pull request against affected workloads; for environments with auto-remediation enabled, the median time from CVE publication to a merged patch PR for high-severity issues is around 90 minutes. For customers who have not enabled auto-remediation, the finding is surfaced in the dashboard with remediation guidance linking to the upstream fix. In either case, HarborGuard re-evaluates affected images on every ingest cycle so the fix status stays current as images are rebuilt and pushed.

See how HarborGuard automates this

Fix available

149.0.7827.115
Affected packages
  • Google / Chrome
    < 149.0.7827.115 (from 149.0.7827.115)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H