CVE-2026-12455: Use after free in Tab Strip in Google Chrome prior to 149
Use after free in Tab Strip in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Metrics
- CVSS v3.1
- 7.5
- Severity
- HIGH
- Fixed in
- 149.0.7827.155
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A use-after-free vulnerability exists in the Tab Strip component of Google Chrome prior to version 149.0.7827.155. The flaw is reachable over the network but requires a victim to perform specific UI gestures on a crafted HTML page, and no authentication to the browser or any service is needed on the attacker's part. Successful exploitation corrupts heap memory and gives an attacker the ability to read sensitive data, modify application state, or crash the browser process. A patched-image rebuild at version 149.0.7827.155 is available on HarborGuard for environments running an affected Chrome version.
HarborGuard Coverage
Detection for CVE-2026-12455 is available across every HarborGuard environment, with the CVE ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle a Chrome or Chromium runtime.
AvailableHarborGuard scores this CVE at 7.5 HIGH using the published CVSS v3.1 vector and can weight that score against each environment's compliance policy to route findings to the appropriate team inbox within the customer organization.
AvailableA patched-image rebuild pinned to Chrome 149.0.7827.155 becomes available on HarborGuard for any image found to carry an affected version. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the crafted HTML page over the network, so the victim's browser must be able to reach attacker-controlled web content.
- AuthenticationNot required
No account or credential of any kind is needed; the attack works against any unauthenticated browser session that loads the malicious page.
- Victim interactionRequired
The victim must be convinced to perform specific UI gestures (such as interacting with browser tabs) on the crafted page, making social engineering a prerequisite.
- Attack complexityDetail
Attack complexity is high, meaning the attacker must account for timing or environmental factors to reliably trigger the heap corruption, reducing the likelihood of a straightforward, condition-free exploit.
Blast Radius
- A successful exploit can read heap memory contents, exposing in-memory session tokens, credentials, or other sensitive page data.
- The attacker can modify heap structures, allowing tampering with browser state or data being processed in the affected tab.
- The vulnerability can be used to crash the Chrome browser process entirely, disrupting the user's session.
- In a fully weaponized exploit chain, heap corruption at this level can serve as a stepping stone toward arbitrary code execution within the browser's renderer or beyond its sandbox.
How HarborGuard Handles This
Available on HarborGuard: any container image that includes a Chrome or Chromium binary older than 149.0.7827.155 is flagged against this CVE within minutes of the advisory entering HarborGuard's feed. For customers with auto-remediation enabled, HarborGuard initiates a rebuild at the patched version, runs regression tests against the resulting image, and opens a pull request against affected workloads. Median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the finding is routed to the designated team inbox with the CVSS 7.5 HIGH score, affected image list, and fix-version details attached for faster human review.
Fix available
- Google / Chrome< 149.0.7827.155 (from 149.0.7827.155)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H