Skip to content
Auto-CTI
Back to today
NEW HIGH A3

CVE-2026-12029 , Use After Free in Video in Google Chrome on Windows prior to 149.0.7827.115

A NVD · · CVE-2026-12029

Admiralty grading (A–F · 1–6)

Source reliability

  • A Completely reliable
  • B Usually reliable
  • C Fairly reliable
  • D Not usually reliable
  • E Unreliable
  • F Cannot be judged

Information credibility

  • 1 Confirmed
  • 2 Probably true
  • 3 Possibly true
  • 4 Doubtful
  • 5 Improbable
  • 6 Cannot be judged

NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.

Key metrics

EPSS
0%

Key insight

The vulnerability requires that the renderer process must already be compromised; exploit potential is therefore limited to scenarios involving prior code execution.

Description

CVE-2026-12029 is a use-after-free vulnerability in the Video component of Google Chrome (versions before 149.0.7827.115 on Windows) that enables a potential sandbox escape. The attack requires that an attacker has already compromised the renderer process and then attempts to break the browser sandbox via a crafted HTML page. The vulnerability is classified with severity 'High'. A PoC or active exploitation is not documented in the NVD description.

Risk score

20
cvss base
0.00
kev bonus
0.00
epss bonus
0.00
poc bonus
0.00
raw before weight
0.00
industry weight
1.21
freshness factor
1.00
exploitability factor
1.00
days old
0.00
vendor mismatch penalty
0.00

Path: operational

ESC