HarborGuard / CVE
Back to search
HIGHCVE-2026-10001Published Modified CNA Chrome

CVE-2026-10001: Use after free in PerformanceManager in Google Chrome prior to 148

Use after free in PerformanceManager in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability in the PerformanceManager component of Google Chrome (versions prior to 148.0.7778.216) allows a remote attacker who has already compromised the renderer process to escape the browser sandbox via a crafted HTML page. The flaw is reachable over the network but requires the victim to interact with attacker-controlled content, and successful exploitation gives the attacker full read, write, and availability impact on the host beyond the sandbox boundary. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version of Chrome.

HarborGuard Coverage

Detection

Detection of CVE-2026-10001 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of publication from upstream feeds, including custom-built images that bundle a Chrome or Chromium binary. Coverage extends to both registry scans and CI/CD pipeline intercepts.

Available
Triage

HarborGuard scores this CVE at 8.3 HIGH using the published CVSS v3.1 vector and surfaces it with per-environment compliance policy weighting to ensure it is routed to the appropriate team inbox inside each customer organization.

Available
Patch

A patched-image rebuild pinned at Chrome 148.0.7778.216 becomes available in HarborGuard the moment the fix version is confirmed in upstream feeds. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite against the updated image, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the victim over the network by serving a crafted HTML page from a remote origin.

  • AuthenticationNot required

    No account or credential is needed; the attacker only needs the victim to load attacker-controlled content.

  • Victim interactionRequired

    The victim must visit or otherwise interact with a crafted HTML page, making this a social-engineering-dependent attack.

  • Attack complexityDetail

    Exploitation is rated High complexity because the attacker must have already compromised the renderer process before the use-after-free can be used for a sandbox escape, introducing a significant precondition.

Blast Radius

  • A successful attacker escapes the Chrome sandbox and gains code execution in the context of the browser process on the host.
  • With sandbox containment removed, the attacker reads files, credentials, and session tokens accessible to the browser process.
  • The attacker can write or modify files and data accessible to the browser process on the underlying host.
  • The attacker can crash or disrupt browser and host-level services that the browser process has access to.

How HarborGuard Handles This

Available on HarborGuard: images containing Google Chrome prior to 148.0.7778.216 are flagged automatically within minutes of CVE publication. For customers who opt into auto-remediation, HarborGuard rebuilds the affected image at the patched version, runs regression tests, and opens a PR against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuilt image and a pre-populated change record are staged and waiting for reviewer sign-off. Because this vulnerability requires a pre-compromised renderer as a stepping stone, customers who cannot immediately rebuild are advised to apply network-policy controls that restrict which origins can deliver content to browser instances running inside containers, reducing the attacker surface while the patch is staged.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H