HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-1220Published Modified CNA Chrome

CVE-2026-1220: Race in V8 in Google Chrome prior to 144

Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
7.5
Severity
HIGH
Fixed in
144.0.7559.99
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A race condition in V8, the JavaScript engine embedded in Google Chrome, allows a remote attacker to trigger type confusion by serving a crafted HTML page to a victim. The vulnerability is reachable over the network but requires the victim to visit a malicious page, and exploitation involves timing-dependent conditions that add complexity. Successful exploitation gives an attacker full read access, write access, and the ability to crash or destabilize the affected browser process, effectively enabling remote code execution in the renderer context. A patched-image rebuild at version 144.0.7559.99 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images, including custom-built images that bundle Chrome or Chromium as a dependency. Any image carrying a Chrome version prior to 144.0.7559.99 is flagged automatically.

Available
Triage

HarborGuard scores this CVE at 7.5 HIGH using the CVSS v3.1 vector and can weight that score against each customer environment's compliance policy to determine urgency. Routed findings are delivered to the inbox configured for the relevant team within each customer organization.

Available
Patch

A patched-image rebuild at Chrome 144.0.7559.99 becomes available through HarborGuard once the fix version is confirmed in the upstream advisory. For customers with auto-remediation enabled, HarborGuard performs the rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the victim over the network by getting them to load a remotely hosted crafted HTML page.

  • AuthenticationNot required

    No account or credential is needed; the attacker only needs the victim to visit a page under the attacker's control.

  • Victim interactionRequired

    The victim must actively open or be redirected to a crafted HTML page, making social engineering or malvertising the primary delivery vector.

  • Attack complexityDetail

    Exploitation is timing-dependent, relying on a race condition inside V8 that requires the attacker to win a narrow execution window, making reliable exploitation harder but not impossible with repeated attempts.

Blast Radius

  • A successful exploit reads browser memory, exposing session tokens, credentials, and other sensitive data held in the renderer process.
  • The attacker gains write primitives within the renderer, allowing modification of in-memory objects and enabling further exploitation steps such as sandbox escape.
  • The browser process can be crashed outright, causing a denial of service for the affected user session.
  • Combined high confidentiality, integrity, and availability impact means a fully weaponized exploit effectively achieves remote code execution in the Chrome renderer context.

How HarborGuard Handles This

Available on HarborGuard: detection fires within minutes of CVE publication for any image carrying Chrome prior to 144.0.7559.99, covering both upstream base images and internally built images that bundle Chromium. A patched-image rebuild at 144.0.7559.99 is available for affected environments. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, executes a regression run, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the finding is routed with full CVSS context and affected-image inventory to the appropriate team inbox. Given the network-reachable, user-interaction delivery path, prioritizing images used in browser-based or kiosk workloads is recommended.

See how HarborGuard automates this

Fix available

144.0.7559.99
Affected packages
  • Google / Chrome
    < 144.0.7559.99 (from 144.0.7559.99)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H