HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-12455Published Modified CNA Chrome

CVE-2026-12455: Use after free in Tab Strip in Google Chrome prior to 149

Use after free in Tab Strip in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
7.5
Severity
HIGH
Fixed in
149.0.7827.155
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability exists in the Tab Strip component of Google Chrome prior to version 149.0.7827.155. The flaw is reachable over the network but requires a victim to perform specific UI gestures on a crafted HTML page, and no authentication to the browser or any service is needed on the attacker's part. Successful exploitation corrupts heap memory and gives an attacker the ability to read sensitive data, modify application state, or crash the browser process. A patched-image rebuild at version 149.0.7827.155 is available on HarborGuard for environments running an affected Chrome version.

HarborGuard Coverage

Detection

Detection for CVE-2026-12455 is available across every HarborGuard environment, with the CVE ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle a Chrome or Chromium runtime.

Available
Triage

HarborGuard scores this CVE at 7.5 HIGH using the published CVSS v3.1 vector and can weight that score against each environment's compliance policy to route findings to the appropriate team inbox within the customer organization.

Available
Patch

A patched-image rebuild pinned to Chrome 149.0.7827.155 becomes available on HarborGuard for any image found to carry an affected version. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the crafted HTML page over the network, so the victim's browser must be able to reach attacker-controlled web content.

  • AuthenticationNot required

    No account or credential of any kind is needed; the attack works against any unauthenticated browser session that loads the malicious page.

  • Victim interactionRequired

    The victim must be convinced to perform specific UI gestures (such as interacting with browser tabs) on the crafted page, making social engineering a prerequisite.

  • Attack complexityDetail

    Attack complexity is high, meaning the attacker must account for timing or environmental factors to reliably trigger the heap corruption, reducing the likelihood of a straightforward, condition-free exploit.

Blast Radius

  • A successful exploit can read heap memory contents, exposing in-memory session tokens, credentials, or other sensitive page data.
  • The attacker can modify heap structures, allowing tampering with browser state or data being processed in the affected tab.
  • The vulnerability can be used to crash the Chrome browser process entirely, disrupting the user's session.
  • In a fully weaponized exploit chain, heap corruption at this level can serve as a stepping stone toward arbitrary code execution within the browser's renderer or beyond its sandbox.

How HarborGuard Handles This

Available on HarborGuard: any container image that includes a Chrome or Chromium binary older than 149.0.7827.155 is flagged against this CVE within minutes of the advisory entering HarborGuard's feed. For customers with auto-remediation enabled, HarborGuard initiates a rebuild at the patched version, runs regression tests against the resulting image, and opens a pull request against affected workloads. Median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the finding is routed to the designated team inbox with the CVSS 7.5 HIGH score, affected image list, and fix-version details attached for faster human review.

See how HarborGuard automates this

Fix available

149.0.7827.155
Affected packages
  • Google / Chrome
    < 149.0.7827.155 (from 149.0.7827.155)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H