CVE-2026-12447: Heap buffer overflow in WebRTC in Google Chrome prior to 149
Heap buffer overflow in WebRTC in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 149.0.7827.155
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A heap buffer overflow in the WebRTC component of Google Chrome prior to version 149.0.7827.155 allows a remote attacker to execute arbitrary code inside the browser sandbox by luring a user to a crafted HTML page. The vulnerability is reachable over the network and requires no authentication, only a single user interaction (visiting a malicious page). Successful exploitation gives the attacker code execution within the Chrome sandbox, with high impact to confidentiality, integrity, and availability. A patched-image rebuild at version 149.0.7827.155 is available on HarborGuard for environments running an affected version of Chrome.
HarborGuard Coverage
Detection is available across every HarborGuard environment, with CVE-2026-12447 ingested from upstream advisory feeds within minutes of publication and matched against customer images, including custom-built images that bundle Chrome or Chromium. Any image in a connected registry or CI pipeline running a Chrome version below 149.0.7827.155 is flagged automatically.
AvailableHarborGuard scores this CVE at 8.8 HIGH using the published CVSS v3.1 vector and weights findings against each customer environment's compliance policy to determine urgency and routing. Findings are dispatched to the appropriate team inbox within each organization based on configured ownership rules.
AvailableA patched-image rebuild pinned to Chrome 149.0.7827.155 is available on HarborGuard for any environment where an affected image is detected. For customers who have auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite against the updated image, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network; the target Chrome instance must be reachable in the sense that the user browses to an attacker-controlled or compromised URL.
- AuthenticationNot required
No account or credential of any kind is required; any unauthenticated remote attacker can serve the malicious page.
- Victim interactionRequired
The user must navigate to a crafted HTML page, making this a social-engineering vector that requires at least one deliberate or tricked browser action.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and imposes no special preconditions such as race conditions or specific memory layout requirements.
Blast Radius
- The attacker executes arbitrary code within the Chrome renderer sandbox, enabling full control of the sandboxed process.
- With sandbox escape (not guaranteed by this CVE alone), the attacker reads files and credentials accessible to the browser process.
- The attacker can modify browser state, inject content into open pages, and exfiltrate session tokens or saved credentials held in memory.
- The affected Chrome process can be crashed or rendered unresponsive, disrupting the user's browsing session and any web-based workflows.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-12447 is active across all connected registries and pipelines, matching images that bundle Chrome below 149.0.7827.155. For environments with auto-remediation enabled, HarborGuard can rebuild the affected image at the patched version, run regression tests, and open a pull request against impacted workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in those environments. Where compliance policy requires manual approval, the finding is routed to the designated team inbox with severity, CVSS vector, and affected image list attached so engineers can act without additional research. Customers who have not yet configured auto-remediation can initiate a manual rebuild from the CVE detail page at any time.
Fix available
- Google / Chrome< 149.0.7827.155 (from 149.0.7827.155)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H