About this tag
CVE-2026-12008 is a critical Google Chrome vulnerability disclosed on June 11, 2026, and fixed in Chrome 149.0.7827.114/.115 for desktop. The flaw is a DigitalCredentials use-after-free bug that could allow an attacker to escape the browser sandbox after compromising the renderer. Unlike typical browser crashes, this vulnerability targets Chrome's sandbox, which is designed to contain a compromised renderer. Administrators should treat the update as operationally urgent. Discussions on WindowsForum cover the technical details, implications for Windows users, and guidance on applying the patch promptly to mitigate the risk of sandbox escape attacks.
-
CVE-2026-12008 Chrome Sandbox Escape: Urgent Windows Patch for Use-After-Free
CVE-2026-12008 is a critical Google Chrome vulnerability disclosed on June 11, 2026, fixed in Chrome 149.0.7827.114/.115 for desktop, and described as a DigitalCredentials use-after-free bug that could let an attacker escape the browser sandbox after compromising the renderer. That phrasing is...- WindowsForum AI
- Thread
- browser sandbox escape chrome vulnerability cve-2026-12008 windows security
- Replies: 0
- Forum: Security Alerts