HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-12448Published Modified CNA Chrome

CVE-2026-12448: Inappropriate implementation in WebView in Google Chrome on Android prior to 149

Inappropriate implementation in WebView in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
149.0.7827.155
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An inappropriate implementation flaw in the WebView component of Google Chrome on Android (versions prior to 149.0.7827.155) allows a remote attacker to escalate privileges by delivering a crafted HTML page to a victim. The attack requires no authentication but does require the victim to visit or interact with the malicious page, making it a network-reachable, user-assisted exploit. Successful exploitation gives the attacker high-impact control over confidentiality, integrity, and availability of the affected process. A patched-image rebuild at version 149.0.7827.155 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-12448 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built Android application images that bundle or vendor the Chrome WebView component. Any image found to contain a vulnerable Chrome version below 149.0.7827.155 is flagged immediately.

Available
Triage

HarborGuard scores this CVE at 8.8 HIGH using the published CVSS v3.1 vector and weights the finding against each environment's compliance policy to determine urgency and routing. Triage findings are delivered to the appropriate team inbox within each customer organization based on their configured policy rules.

Available
Patch

A patched-image rebuild pinned to Chrome 149.0.7827.155 is available on HarborGuard for any environment where a vulnerable image is detected. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the crafted HTML page over the network, so the vulnerable service or browser session must be reachable from the attacker's origin.

  • AuthenticationNot required

    No account or credential of any kind is required; the attack works against any unauthenticated user who loads the page.

  • Victim interactionRequired

    The victim must visit or be directed to the attacker-controlled HTML page, requiring a social-engineering or redirect step to succeed.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and requires no special race conditions, memory-layout knowledge, or environmental prerequisites beyond getting the victim to load the page.

Blast Radius

  • A successful attacker escalates privileges within the Chrome WebView sandbox, gaining the ability to read sensitive data stored or processed by the WebView context, including session tokens, cookies, and locally cached content.
  • The attacker can write or modify data accessible to the escalated privilege level, including injecting content into the WebView or altering application state.
  • The attacker can crash or deny service to the affected WebView process, disrupting the Android application relying on it.
  • Because all three CVSS impact dimensions are rated High, the attacker effectively achieves full compromise of confidentiality, integrity, and availability within the affected component boundary.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-12448 is active and matches any image containing Chrome on Android below version 149.0.7827.155, including images where the WebView component is bundled as part of a custom application layer. For customers who opt into auto-remediation, HarborGuard rebuilds the affected image at the fixed version (149.0.7827.155), runs a regression test pass, and opens a pull request against affected workloads. For high-severity CVEs like this one, the median time from CVE publication to a merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval before merging, the rebuilt image and test results are staged and routed to the designated reviewer inbox for sign-off.

See how HarborGuard automates this

Fix available

149.0.7827.155
Affected packages
  • Google / Chrome
    < 149.0.7827.155 (from 149.0.7827.155)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H