CVE-2026-12451: Use after free in DigitalCredentials in Google Chrome prior to 149
Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 149.0.7827.155
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A use-after-free vulnerability exists in the DigitalCredentials component of Google Chrome versions prior to 149.0.7827.155. The flaw is reachable over the network and requires no authentication, but does require an attacker who has already compromised the renderer process to convince a victim to visit a crafted HTML page. Successful exploitation enables a sandbox escape, giving the attacker the ability to read sensitive data, tamper with system state, and crash or destabilize the affected process outside the browser sandbox. A patched-image rebuild at version 149.0.7827.155 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle Chrome or Chromium-derived components.
AvailableHarborGuard scores this finding at 8.3 HIGH using the recorded CVSS v3.1 vector, and per-environment compliance policy weighting is applied to prioritize and route the alert to the appropriate team inbox within each customer organization.
AvailableA patched-image rebuild at Chrome 149.0.7827.155 is available through HarborGuard for any environment where an affected version is detected. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the crafted HTML page over the network, so the target host must be reachable and the victim must browse to the attacker-controlled content.
- AuthenticationNot required
No account or credential is needed to serve the malicious page; the attack begins as an anonymous network interaction.
- Victim interactionRequired
The victim must open a crafted HTML page, meaning the attacker depends on a social-engineering or drive-by step to get the browser to load the content.
- Attack complexityDetail
Exploitation is rated high complexity because it requires the attacker to have already compromised the renderer process before the use-after-free primitive can be used for sandbox escape, introducing a significant prerequisite condition.
Blast Radius
- The attacker escapes the Chrome renderer sandbox, gaining code execution in a less-restricted host process context.
- Sensitive data accessible to the browser process, including stored credentials, session tokens, and page content from other origins, becomes readable.
- The attacker can modify files, registry entries, or other persisted state reachable by the browser process on the host.
- The affected Chrome process and dependent services can be crashed or rendered unavailable.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-12451 is active across all connected environments, matching any image that packages a Chrome or Chromium binary below version 149.0.7827.155. A patched-image rebuild at the fixed version is available immediately. For customers with auto-remediation enabled, HarborGuard initiates a rebuild at 149.0.7827.155, runs regression tests against the updated image, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the finding is routed to the designated team inbox with the CVSS 8.3 HIGH score and full vector detail attached for expedited review.
Fix available
- Google / Chrome< 149.0.7827.155 (from 149.0.7827.155)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H