CVE-2026-10001: Use after free in PerformanceManager in Google Chrome prior to 148
Use after free in PerformanceManager in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
A use-after-free vulnerability in the PerformanceManager component of Google Chrome (versions prior to 148.0.7778.216) allows a remote attacker who has already compromised the renderer process to escape the browser sandbox via a crafted HTML page. The flaw is reachable over the network but requires the victim to interact with attacker-controlled content, and successful exploitation gives the attacker full read, write, and availability impact on the host beyond the sandbox boundary. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version of Chrome.
HarborGuard Coverage
Detection of CVE-2026-10001 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of publication from upstream feeds, including custom-built images that bundle a Chrome or Chromium binary. Coverage extends to both registry scans and CI/CD pipeline intercepts.
AvailableHarborGuard scores this CVE at 8.3 HIGH using the published CVSS v3.1 vector and surfaces it with per-environment compliance policy weighting to ensure it is routed to the appropriate team inbox inside each customer organization.
AvailableA patched-image rebuild pinned at Chrome 148.0.7778.216 becomes available in HarborGuard the moment the fix version is confirmed in upstream feeds. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite against the updated image, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker must reach the victim over the network by serving a crafted HTML page from a remote origin.
- AuthenticationNot required
No account or credential is needed; the attacker only needs the victim to load attacker-controlled content.
- Victim interactionRequired
The victim must visit or otherwise interact with a crafted HTML page, making this a social-engineering-dependent attack.
- Attack complexityDetail
Exploitation is rated High complexity because the attacker must have already compromised the renderer process before the use-after-free can be used for a sandbox escape, introducing a significant precondition.
Blast Radius
- A successful attacker escapes the Chrome sandbox and gains code execution in the context of the browser process on the host.
- With sandbox containment removed, the attacker reads files, credentials, and session tokens accessible to the browser process.
- The attacker can write or modify files and data accessible to the browser process on the underlying host.
- The attacker can crash or disrupt browser and host-level services that the browser process has access to.
How HarborGuard Handles This
Available on HarborGuard: images containing Google Chrome prior to 148.0.7778.216 are flagged automatically within minutes of CVE publication. For customers who opt into auto-remediation, HarborGuard rebuilds the affected image at the patched version, runs regression tests, and opens a PR against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuilt image and a pre-populated change record are staged and waiting for reviewer sign-off. Because this vulnerability requires a pre-compromised renderer as a stepping stone, customers who cannot immediately rebuild are advised to apply network-policy controls that restrict which origins can deliver content to browser instances running inside containers, reducing the attacker surface while the patch is staged.
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H