HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-12023Published Modified CNA Chrome

CVE-2026-12023: Use after free in GPU in Google Chrome on Mac prior to 149

Use after free in GPU in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
149.0.7827.115
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

Use-after-free in the GPU component of Google Chrome on macOS affects versions prior to 149.0.7827.115. The vulnerability is reachable over the network, requires no authentication, but does require the attacker to have already compromised the renderer process and to lure a victim into visiting a crafted HTML page. Successful exploitation allows the attacker to escape Chrome's sandbox, gaining the ability to read, modify, or disrupt data and processes outside the browser's isolated environment. A patched-image rebuild at version 149.0.7827.115 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-12023 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI pipelines, including custom-built images that bundle Chromium or Chrome on macOS base layers.

Available
Triage

HarborGuard is capable of scoring this CVE at CVSS 8.3 (HIGH) and weighting it against each environment's compliance policy to surface it at the appropriate severity level; routing to the correct team or inbox within each customer organization is handled automatically based on configured ownership rules.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.115 is available on HarborGuard for any environment where an affected version is detected. For customers who opt into auto-remediation, HarborGuard rebuilds the image, runs a regression test suite, and opens a PR against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing a victim to a crafted HTML page hosted on an attacker-controlled server.

  • AuthenticationNot required

    No account or credential is needed; the attack is reachable by any unauthenticated visitor to the malicious page.

  • Victim interactionRequired

    The victim must open a crafted HTML page in the browser, requiring the attacker to socially engineer a click or redirect.

  • Attack complexityDetail

    Attack complexity is high, meaning the attacker must first have compromised the renderer process before the use-after-free in the GPU layer can be weaponized for sandbox escape.

Blast Radius

  • The attacker escapes Chrome's sandbox and gains code execution in the context of the browser process on the host macOS system.
  • Confidential data accessible to the browser process, including stored credentials, session tokens, and local file paths, becomes readable.
  • The attacker can modify files and state outside the sandbox, including writing to the user's home directory or injecting into other processes.
  • The browser process and dependent services can be crashed or disrupted, causing loss of availability for the affected user session.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-12023 is active across all customer environments the moment the CVE is ingested, covering any image that includes an affected Chrome or Chromium build on a macOS layer. Because this is a HIGH-severity issue with a confirmed fix, a rebuilt image at Chrome 149.0.7827.115 becomes available for affected environments immediately upon detection. For customers who opt into auto-remediation, HarborGuard rebuilds the affected image, executes a regression run, and opens a pull request against each affected workload; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuilt image and a triage summary are queued for review in the customer's configured inbox. Note that this CVE requires a pre-compromised renderer process as a prerequisite, so teams should also review alerts for any CVEs affecting the Chrome renderer layer alongside this one.

See how HarborGuard automates this

Fix available

149.0.7827.115
Affected packages
  • Google / Chrome
    < 149.0.7827.115 (from 149.0.7827.115)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H