CVE-2026-12445: Use after free in Extensions in Google Chrome prior to 149
Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
Metrics
- CVSS v3.1
- 7.5
- Severity
- HIGH
- Fixed in
- 149.0.7827.155
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A use-after-free vulnerability in the Extensions subsystem of Google Chrome allows an attacker who convinces a user to install a malicious extension to corrupt heap memory. The attack is reachable over the network but requires the victim to take a deliberate installation action, and no authentication to Chrome or a remote service is needed. Successful exploitation gives the attacker full read, write, and crash capabilities within the browser process, which can translate to arbitrary code execution or full data disclosure. A patched-image rebuild at version 149.0.7827.155 is available on HarborGuard for environments running an affected Chrome version.
HarborGuard Coverage
Detection of CVE-2026-12445 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that bundle a Chrome binary.
AvailableHarborGuard scores this finding at CVSS 7.5 (High) and weights it against each environment's compliance policy to determine urgency and routing, directing alerts to the appropriate team inbox within each customer organization.
AvailableA patched-image rebuild pinned to Chrome 149.0.7827.155 becomes available on HarborGuard once the upstream fix is confirmed. For customers who opt into auto-remediation, HarborGuard runs a rebuilt image through regression testing and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker must reach the victim over the network, typically by distributing the malicious extension through the Chrome Web Store or another internet-accessible channel.
- AuthenticationNot required
No authentication to Chrome or any remote service is required; the attacker only needs to persuade the victim to install the extension.
- Victim interactionRequired
The victim must actively install a malicious Chrome extension, making social engineering the primary delivery mechanism.
- Attack complexityDetail
Exploitation is rated High complexity, meaning the attacker must account for heap layout or timing conditions to reliably trigger the use-after-free and achieve code execution.
Blast Radius
- An attacker gains the ability to read browser memory, exposing stored credentials, session cookies, and any data loaded in open tabs.
- Heap corruption with write primitives allows the attacker to modify in-memory browser state, including security boundaries and stored form data.
- The affected Chrome process can be crashed or destabilized, causing denial of service for the user's browsing session.
- Combined high confidentiality, integrity, and availability impact means a fully weaponized exploit achieves arbitrary code execution within the browser's privilege context.
How HarborGuard Handles This
Available on HarborGuard: images containing a Chrome binary older than 149.0.7827.155 are flagged immediately upon CVE ingestion. For customers who opt into auto-remediation, HarborGuard rebuilds the image at the patched version, runs the configured regression suite, and opens a pull request against affected workloads; for High-severity issues, median time from CVE publication to a merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy does not permit automatic remediation, the finding is routed to the designated team inbox with CVSS scoring and fix-version details attached so engineers can act on it manually. Because this vulnerability requires victim interaction via extension installation, teams that cannot patch immediately should consider restricting extension installation through enterprise Chrome policy as a compensating control.
Fix available
- Google / Chrome< 149.0.7827.155 (from 149.0.7827.155)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H