HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-12440Published Modified CNA Chrome

CVE-2026-12440: Use after free in DigitalCredentials in Google Chrome on Windows prior to 149

Use after free in DigitalCredentials in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Metrics

CVSS v3.1
9.6
Severity
CRITICAL
Fixed in
149.0.7827.155
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability exists in the DigitalCredentials component of Google Chrome on Windows, affecting all versions prior to 149.0.7827.155. The flaw is reachable over the network and requires no authentication, though a victim must visit a crafted HTML page. Successful exploitation enables a sandbox escape, giving the attacker full confidentiality, integrity, and availability impact on the host. A patched-image rebuild at version 149.0.7827.155 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-12440 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of ingestion from upstream feeds, including custom-built images that bundle a Chrome installation. Coverage applies to both registry-resident images and images evaluated mid-pipeline during CI/CD runs.

Available
Triage

HarborGuard scores this CVE at 9.6 CRITICAL using the CVSS v3.1 vector and is capable of weighting that score against each customer environment's compliance policy to determine escalation priority. Triage routing to the appropriate team or inbox within each customer organization is available based on configured policy rules.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.155 is available on HarborGuard for any environment found to be running an affected version. For customers with auto-remediation enabled, HarborGuard can perform the rebuild, run a regression test suite against the updated image, and open a PR against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the victim over the network by serving a crafted HTML page, as indicated by AV:N in the CVSS vector.

  • AuthenticationNot required

    No account or credential is needed on the target system prior to exploitation, as indicated by PR:N.

  • Victim interactionRequired

    The victim must navigate to or open a crafted HTML page, making browser-delivered social engineering a prerequisite, as indicated by UI:R.

  • Attack complexityDetail

    The exploit is reliable and imposes no special environmental conditions or race-window requirements on the attacker, as indicated by AC:L.

Blast Radius

  • A successful attacker escapes the Chrome renderer sandbox and gains code execution at the browser process privilege level on the Windows host.
  • With confidentiality impact rated High, the attacker reads files, stored credentials, and session tokens accessible to the browser process.
  • With integrity impact rated High, the attacker writes or modifies data on the host, including files and registry entries reachable by the browser process.
  • With availability impact rated High, the attacker disrupts or terminates the browser process and any dependent services, causing a denial of service on the affected system.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-12440 is active across ingest cycles and matches any image shipping a Chrome version below 149.0.7827.155. Where compliance policy permits, a patched-image rebuild at 149.0.7827.155 is queued automatically upon detection. For customers who opt into auto-remediation, HarborGuard performs the rebuild, executes a regression run against the updated image, and opens a PR against affected workloads. For high and critical severity issues, the median time from CVE publication to a merged patch PR is around 90 minutes in environments with auto-remediation enabled. Customers who manage remediation manually can retrieve the flagged image list from the HarborGuard dashboard and prioritize based on the CRITICAL severity rating and the sandbox-escape impact of this flaw.

See how HarborGuard automates this

Fix available

149.0.7827.155
Affected packages
  • Google / Chrome
    < 149.0.7827.155 (from 149.0.7827.155)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H