CVE-2026-12467: High Use after free in Extensions
Chromium: CVE-2026-12467 Use after free in Extensions
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 149.0.4022.80 - Upgrade
Upgrade
Google Chrome (Chromium-based)to a version that resolves this vulnerability.Fixed in 149.0.7827.155 - Compensating control
Assuming a compromised renderer process is a threat scenario, restrict access to untrusted content that could exploit the Extensions use-after-free via crafted HTML pages until Chrome is updated to 149.0.7827.155 or later.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2026-12467?
The severity of CVE-2026-12467 is classified as High.
How do I fix CVE-2026-12467?
To fix CVE-2026-12467, update Google Chrome to version 149.0.7827.155 or later.
What is CVE-2026-12467?
CVE-2026-12467 is a vulnerability in Google Chrome that involves a use after free issue in the Extensions component.
What kind of impact does CVE-2026-12467 have?
CVE-2026-12467 can allow a remote attacker to potentially perform a sandbox escape via a crafted HTML page.
Which version of Google Chrome is affected by CVE-2026-12467?
Google Chrome versions prior to 149.0.7827.155 are affected by CVE-2026-12467.