CVE-2026-10003: Use after free in Views in Google Chrome prior to 148
Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
A use-after-free vulnerability in the Views component of Google Chrome allows a remote attacker to execute arbitrary code on the victim's machine. Exploitation requires the attacker to deliver a crafted HTML page and convince a user to perform specific UI gestures, making it a social-engineering-assisted attack reachable over the network; no authentication is needed, but the attack is not trivially reliable due to high complexity conditions. Successful exploitation gives the attacker full code execution inside the browser process, with access to sensitive data and the ability to modify or disrupt the user's session. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection of CVE-2026-10003 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that bundle a Chrome or Chromium binary.
AvailableHarborGuard scores this CVE at 7.5 HIGH using the published CVSS v3.1 vector and can weight that score against each customer organization's compliance policy to route findings to the appropriate team inbox automatically.
AvailableA patched-image rebuild targeting Chrome 148.0.7778.216 becomes available on HarborGuard for any image found to carry an affected version. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers a crafted HTML page over the network, so the victim's browser must be reachable through normal web browsing.
- AuthenticationNot required
No account, credential, or prior authentication of any kind is required; the attacker only needs the victim to visit a malicious page.
- Victim interactionRequired
Exploitation depends on convincing the victim to perform specific UI gestures on the crafted page, requiring a social-engineering step before the vulnerability fires.
- Attack complexityDetail
The CVSS vector marks complexity as High, meaning the attacker must account for environmental factors such as memory layout or precise timing to reliably trigger the use-after-free condition.
Blast Radius
- Arbitrary code executes inside the Chrome browser process on the victim's machine, giving the attacker control over the browser's execution context.
- The attacker can read sensitive in-browser data including session tokens, saved credentials, and page contents from any open tab.
- The attacker can modify in-browser state, inject content into pages, and tamper with data the user submits through the browser.
- The browser process can be crashed or rendered unresponsive, disrupting the user's active session and any dependent workflows.
How HarborGuard Handles This
Available on HarborGuard: images containing Google Chrome versions below 148.0.7778.216 are flagged automatically as soon as the CVE matches during a registry or pipeline scan. Where a customer's compliance policy permits auto-remediation, HarborGuard rebuilds the image at the patched version, runs a regression test pass, and opens a pull request against affected workloads; for high-severity CVEs the median time from publication to a merged patch PR is around 90 minutes. For environments where auto-remediation is not enabled, the finding is routed to the designated team inbox with the CVSS score, vector breakdown, and the specific image layers containing the vulnerable Chrome binary, so engineers have the context they need to act manually. Until a rebuild is deployed, network-policy controls that restrict which workloads can serve or render arbitrary external HTML reduce exposure to the social-engineering delivery path this CVE depends on.
Metrics
- CVSS v3.1
- 7.5
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H