HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-12467Published Modified CNA Chrome

CVE-2026-12467: Use after free in Extensions in Google Chrome prior to 149

Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
149.0.7827.155
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

Use-after-free in the Extensions subsystem of Google Chrome (versions prior to 149.0.7827.155) allows a remote attacker who has already compromised the renderer process to escape the browser sandbox via a crafted HTML page. The attacker must lure a victim into visiting a malicious page, and exploitation requires overcoming a high-complexity memory condition, but no authentication is needed. Successful exploitation grants the attacker full read, write, and availability impact outside the browser sandbox, potentially leading to arbitrary code execution on the host. A patched-image rebuild at version 149.0.7827.155 is available on HarborGuard for environments running an affected version of Chrome.

HarborGuard Coverage

Detection

Detection of CVE-2026-12467 is available across every HarborGuard environment, with the CVE ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle Google Chrome. Any image containing a Chrome version prior to 149.0.7827.155 is flagged automatically.

Available
Triage

HarborGuard scores this CVE at 8.3 HIGH using the CVSS v3.1 vector and surfaces findings weighted against each customer environment's compliance policy, routing alerts to the appropriate team inbox within each organization. Per-environment context (such as whether Chrome is exposed at a network boundary) is factored into prioritization.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.155 becomes available on HarborGuard for any environment where an affected image is detected. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the crafted HTML page over the network, so the target Chrome instance must be reachable or the user must browse to an attacker-controlled origin.

  • AuthenticationNot required

    No account or credentials are needed; the exploit is delivered through a publicly accessible crafted web page.

  • Victim interactionRequired

    The victim must visit or be redirected to a crafted HTML page, making this a social-engineering-dependent exploit.

  • Attack complexityDetail

    Exploitation is rated High complexity because the attacker must have already compromised the renderer process and must satisfy memory-state conditions for the use-after-free to be reliably triggered.

Blast Radius

  • Attacker escapes the Chrome sandbox, gaining code execution in the context of the browser process on the host system.
  • Confidential data accessible to the browser (stored credentials, session tokens, local files) becomes readable outside the sandbox.
  • The attacker can write to or modify data on the host filesystem or inject code into other processes running under the same user account.
  • The host process can be crashed or disrupted, denying service to the affected user session.

How HarborGuard Handles This

Available on HarborGuard: any container image bundling Google Chrome prior to 149.0.7827.155 is matched against this CVE within minutes of the advisory entering upstream feeds. For customers who opt into auto-remediation, HarborGuard rebuilds the image at Chrome 149.0.7827.155, executes a regression run, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled. Where compliance policy requires manual approval, the finding is routed to the designated team inbox with CVSS scoring and environment context attached. Customers who cannot immediately upgrade should consider network-policy controls that restrict which workloads can initiate outbound browser sessions, reducing the social-engineering surface while the patch is staged.

See how HarborGuard automates this

Fix available

149.0.7827.155
Affected packages
  • Google / Chrome
    < 149.0.7827.155 (from 149.0.7827.155)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H