CVE-2026-12468: Race in Updater in Google Chrome on Mac prior to 149
Race in Updater in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 149.0.7827.155
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A race condition in the Google Chrome updater component on macOS allows a remote attacker who has already compromised the renderer process to escape the browser sandbox via a crafted HTML page. The vulnerability is reachable over the network but requires victim interaction and high attack complexity due to the race window involved. Successful exploitation gives the attacker full confidentiality, integrity, and availability impact outside the sandbox, effectively granting arbitrary code execution on the host. A patched-image rebuild at version 149.0.7827.155 is available on HarborGuard for environments running an affected version of Chrome on Mac.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle Chrome on macOS base layers.
AvailableHarborGuard scores this CVE at CVSS 8.3 (High) and can weight that score against each environment's compliance policy to determine urgency; findings are routed to the appropriate team inbox within each customer organization based on configured ownership rules.
AvailableA patched-image rebuild pinned to Chrome 149.0.7827.155 becomes available on HarborGuard for any image found to include an affected version. For customers who opt into auto-remediation, HarborGuard runs the rebuild, executes regression tests, and opens a PR against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the crafted HTML page over the network, so the affected service must be reachable remotely.
- AuthenticationNot required
No account or credentials are needed to initiate the attack; any user browsing to the attacker-controlled page is a valid target.
- Victim interactionRequired
The targeted user must visit a crafted HTML page, making this a social-engineering vector that requires the victim to take an action.
- Attack complexityDetail
Exploitation depends on winning a race condition in the updater, meaning the attacker must time the exploit correctly and success is not guaranteed on every attempt.
Blast Radius
- An attacker who wins the race condition escapes the Chrome renderer sandbox and gains code execution at a higher privilege level on the host macOS system.
- With sandbox escape achieved, the attacker can read files and credentials stored outside the browser profile, including keychain entries and session tokens accessible to the user account.
- The attacker can write or modify files on the filesystem, enabling persistence mechanisms such as launch agents or modification of application binaries.
- The attacker can crash or terminate processes on the host, disrupting any service or application running under the compromised user account.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-12468 is active against any image that packages Google Chrome below 149.0.7827.155 on a macOS base layer. Where a matching image is found, a rebuild pinned to the fixed version (149.0.7827.155) is made available. For customers who opt into auto-remediation, HarborGuard runs the rebuild, executes regression tests, and opens a PR against affected workloads; for High-severity issues, the median time from CVE publication to a merged patch PR in auto-remediation environments is around 90 minutes. For environments where auto-remediation is not enabled, the finding is surfaced in the HarborGuard dashboard with CVSS severity and affected image details so the responsible team can act manually. Given the sandbox-escape nature of this vulnerability and its High CVSS score, prioritizing rapid image updates is strongly advised.
Fix available
- Google / Chrome< 149.0.7827.155 (from 149.0.7827.155)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H