CVE-2026-12443: Use after free in Web Authentication in Google Chrome prior to 149
Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 149.0.7827.155
- Affected Products
- 1
HarborGuard Analysis
Synopsis
Use-after-free in the Web Authentication component of Google Chrome (versions prior to 149.0.7827.155) allows a remote attacker to execute arbitrary code by delivering a crafted HTML page to a target user. The vulnerability is reachable over the network and requires no authentication, though the victim must open a malicious page. Successful exploitation gives the attacker full code execution inside the browser process, with high impact on confidentiality, integrity, and availability. A patched-image rebuild at 149.0.7827.155 is available on HarborGuard for environments running an affected version of Chrome.
HarborGuard Coverage
Detection of CVE-2026-12443 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle a Chrome or Chromium binary.
AvailableHarborGuard scores this CVE at 8.8 HIGH (CVSS v3.1) and is capable of weighting that score against each environment's compliance policy to prioritize routing and alert delivery to the appropriate team inbox within each customer organization.
AvailableA patched-image rebuild at Chrome 149.0.7827.155 is available on HarborGuard for any image found to carry an affected version. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network by directing the victim to an attacker-controlled or compromised web page; the Chrome instance must be reachable through normal browser traffic.
- AuthenticationNot required
No account or credential of any kind is needed; any unauthenticated remote party can serve the malicious page.
- Victim interactionRequired
The target user must open or be redirected to the crafted HTML page, making this a social-engineering or watering-hole delivery scenario.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and requires no special race conditions, memory-layout prerequisites, or environmental timing.
Blast Radius
- Reads in-browser secrets including stored credentials, session cookies, and Web Authentication (WebAuthn) key material accessible to the browser process.
- Modifies browser state and can write to the local filesystem or interact with OS resources within the scope of the browser process privilege level.
- Crashes or destabilizes the affected Chrome process, disrupting the user's active session and any services relying on browser-based authentication flows.
- Provides a foothold for further exploitation of the underlying host if the browser is running with elevated or container-escape-prone privileges.
How HarborGuard Handles This
Available on HarborGuard: images carrying a Chrome or Chromium binary older than 149.0.7827.155 are flagged automatically as the CVE is matched against each ingest cycle. For customers who opt into auto-remediation, HarborGuard rebuilds the image at the patched version, runs regression tests, and opens a pull request against affected workloads, with a median time to merged patch PR of around 90 minutes for high-severity issues. Where compliance policy requires manual approval, the rebuild artifact is staged and the pull request is held in a pending state until a reviewer approves. Because this vulnerability requires victim interaction via a browser, teams that cannot immediately rebuild should also consider restricting which container workloads expose Chrome to untrusted web content and auditing any service accounts tied to WebAuthn flows for scope reduction.
Fix available
- Google / Chrome< 149.0.7827.155 (from 149.0.7827.155)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H