HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-12028Published Modified CNA Chrome

CVE-2026-12028: Use after free in GPU in Google Chrome on Android prior to 149

Use after free in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
149.0.7827.115
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability in the GPU component of Google Chrome on Android affects all Chrome versions prior to 149.0.7827.115. The flaw is reachable over the network by a remote attacker who has already compromised the renderer process, with no authentication required but requiring victim interaction via a crafted HTML page. Successful exploitation enables a sandbox escape, granting the attacker capabilities beyond the Chrome renderer sandbox including high-impact read, write, and availability effects on the host. A patched-image rebuild at version 149.0.7827.115 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-12028 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of ingestion from upstream feeds, including custom-built Android container images that bundle a Chrome runtime. Coverage extends to both registry scans and in-pipeline image checks at build time.

Available
Triage

HarborGuard is capable of scoring this CVE at CVSS 8.3 HIGH and weighting it against each environment's compliance policy to determine urgency. Triage routing is available to direct alerts to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.115 is available on HarborGuard for any environment found running an affected version. For customers who opt into auto-remediation, HarborGuard can perform the rebuild, run regression tests, and open a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the victim over the network by delivering a crafted HTML page, requiring over-the-network exposure to the target.

  • AuthenticationNot required

    No authentication or account credentials are required; the attacker operates as an unauthenticated remote party.

  • Victim interactionRequired

    The victim must visit or load a crafted HTML page, making this a social-engineering vector requiring at least one user action.

  • Attack complexityDetail

    Attack complexity is high, meaning the attacker must first have compromised the renderer process before leveraging this flaw, introducing a prerequisite environmental condition.

Blast Radius

  • A successful attacker escapes the Chrome renderer sandbox, gaining execution capabilities outside the restricted process boundary.
  • Confidential data accessible to the Chrome process on the Android device, including stored credentials, session tokens, and browsing data, becomes readable.
  • The attacker can write or modify data within the scope accessible after the sandbox escape, including files and application state on the device.
  • The availability of the Chrome process and potentially dependent application services can be disrupted or crashed.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-12028 is active across customer image scans and build pipelines the moment the CVE is ingested from upstream feeds. For environments running Chrome on Android at a version below 149.0.7827.115, a patched-image rebuild at the fix version is available. For customers who opt into auto-remediation, HarborGuard triggers a rebuild at 149.0.7827.115, runs a regression test suite against the rebuilt image, and opens a pull request against affected workloads; for high-severity issues, the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy restricts auto-remediation, the CVE is flagged for manual review and routed to the configured owner inbox with full CVSS context attached.

See how HarborGuard automates this

Fix available

149.0.7827.115
Affected packages
  • Google / Chrome
    < 149.0.7827.115 (from 149.0.7827.115)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H