HarborGuard / CVE
Back to search
HIGHCVE-2026-10007Published Modified CNA Chrome

CVE-2026-10007: Use after free in SVG in Google Chrome prior to 148

Use after free in SVG in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability in Google Chrome's SVG rendering engine allows a remote attacker to execute arbitrary code inside the browser sandbox. The attack is reachable over the network and requires no authentication, but does require the victim to visit a crafted HTML page. Successful exploitation gives an attacker code execution within the Chrome sandbox, which can be combined with a sandbox escape to achieve full compromise of the host process. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection capability is available across every HarborGuard environment; CVE-2026-10007 is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle a Chromium or Chrome runtime. Any image carrying a Chrome version below 148.0.7778.216 is flagged automatically.

Available
Triage

HarborGuard scores this CVE at 8.8 HIGH using the published CVSS v3.1 vector and weights it against each customer environment's compliance policy to determine urgency and routing. Triage alerts are delivered to the team inbox configured inside each customer org, prioritized according to their policy thresholds.

Available
Patch

A patched-image rebuild pinned to Chrome 148.0.7778.216 is available on HarborGuard for any environment whose scanned images contain an affected version. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite against the updated image, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by luring the victim to a crafted HTML page hosted on an attacker-controlled server.

  • AuthenticationNot required

    No account or credential of any kind is required; any user browsing to the malicious page is a viable target.

  • Victim interactionRequired

    The victim must open the attacker-crafted HTML page, meaning the attack depends on a social-engineering step such as a phishing link or malicious advertisement.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental factors.

Blast Radius

  • The attacker gains arbitrary code execution inside the Chrome renderer sandbox, enabling reads of in-memory session tokens, page content, and credentials entered in the browser.
  • Attacker-controlled code running in the renderer can modify in-memory DOM state and intercept or tamper with data the user submits to web applications.
  • The compromised renderer process can be used as a stepping stone for a secondary sandbox-escape exploit, potentially giving the attacker full control of the host process.
  • Confidentiality, integrity, and availability of the browser process are all fully compromised once the exploit lands.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-10007 is active across all scanning pipelines the moment the CVE was published, covering any image that bundles a Chrome or Chromium binary below 148.0.7778.216. A rebuilt image at the fixed version is available for environments where an affected image is detected. For customers who opt into auto-remediation, HarborGuard performs the rebuild, validates it against the regression suite, and opens a pull request against affected workloads; for high-severity CVEs like this one, the median time from publication to merged patch PR is around 90 minutes. Where compliance policy does not permit auto-remediation, the triage alert is routed to the designated team inbox with CVSS score, affected image list, and the recommended upgrade target, so engineers can act manually with full context.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H