CVE-2026-10000: Use after free in Passwords in Google Chrome on Windows prior to 148
Use after free in Passwords in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
Use-after-free in the Passwords component of Google Chrome on Windows (versions prior to 148.0.7778.216) allows a remote attacker who has already compromised the browser renderer process to escape the Chrome sandbox by delivering a crafted HTML page. The vulnerability is reachable over the network and requires no authentication, though the attacker must first achieve renderer compromise and persuade a user to visit a malicious page. Successful exploitation gives the attacker full control outside the sandbox, enabling arbitrary code execution, data theft, and system tampering at the level of the browser process. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version of Chrome.
HarborGuard Coverage
Detection of CVE-2026-10000 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle a Chrome or Chromium installation.
AvailableHarborGuard is capable of surfacing this CVE with its CVSS v3.1 score of 8.3 (High) and weighting it against each environment's compliance policy, then routing the finding to the appropriate team inbox within the customer organization.
AvailableA patched-image rebuild at Chrome 148.0.7778.216 becomes available on HarborGuard for any image found to carry an affected version. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker must reach the victim's browser over the network by serving a crafted HTML page from a remote origin.
- AuthenticationNot required
No authentication or account credentials are required; the attacker operates as an anonymous remote party.
- Victim interactionRequired
The victim must visit or be redirected to the attacker-controlled HTML page, making this a social-engineering or drive-by delivery scenario.
- Attack complexityDetail
Exploitation is high-complexity because it requires a precondition of renderer process compromise before the sandbox-escape primitive can be triggered.
Blast Radius
- Attacker escapes the Chrome sandbox and executes arbitrary code at the privilege level of the browser process on the Windows host.
- Confidential data accessible to the browser, including saved passwords, session cookies, and locally cached files, is readable by the attacker.
- Attacker can write or modify files and registry keys that the browser process has access to, altering persisted application state.
- The browser process and any dependent services can be crashed or destabilized, disrupting the user's session and any locally running workloads.
How HarborGuard Handles This
Available on HarborGuard: any image in a connected registry or pipeline that bundles Chrome prior to 148.0.7778.216 on Windows is flagged against this CVE within minutes of the advisory appearing in upstream feeds. The finding is scored at CVSS 8.3 (High) and routed according to each environment's compliance policy. Where compliance policy permits auto-remediation, HarborGuard rebuilds the image at Chrome 148.0.7778.216, runs a regression test run, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled. For environments that do not opt into auto-remediation, the rebuilt image at the fix version is staged and available for manual promotion. Until a rebuild is deployed, teams should consider network-policy controls that limit which internal services can be reached from workloads running the affected Chrome version, and evaluate whether any CI pipelines or automated browser-test runners are exposed to untrusted HTML input.
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H