CVE-2026-10012: Use after free in Skia in Google Chrome prior to 148
Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
A use-after-free vulnerability in the Skia graphics library affects Google Chrome versions prior to 148.0.7778.216. The flaw is reachable over the network and requires no authentication, but does require the attacker to have already compromised the Chrome renderer process and to trick the victim into visiting a crafted HTML page. Successful exploitation enables a sandbox escape, giving the attacker capabilities beyond the browser sandbox including potential code execution on the host. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle Chrome or Chromium. Any image carrying a Chrome version below 148.0.7778.216 is flagged automatically.
AvailableHarborGuard scores this CVE at CVSS 8.3 (HIGH) and weights it against each environment's compliance policy to determine urgency and routing. Findings are dispatched to the appropriate team inbox within the customer org based on image ownership and policy configuration.
AvailableA patched-image rebuild at Chrome 148.0.7778.216 becomes available on HarborGuard for any environment running an affected version. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test pass, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network by directing the victim to a crafted HTML page hosted remotely.
- AuthenticationNot required
No credentials or account access are required to initiate the attack.
- Victim interactionRequired
The victim must navigate to or be redirected to the attacker-controlled HTML page for the exploit to trigger.
- Attack complexityDetail
Attack complexity is high: the attacker must first have compromised the Chrome renderer process before this vulnerability can be leveraged for a sandbox escape, introducing a significant prerequisite condition.
Blast Radius
- A successful attacker escapes the Chrome sandbox, gaining execution context outside the browser's isolation boundary.
- Confidential data accessible to the browser process, including stored credentials, session tokens, and local files, becomes readable by the attacker.
- The attacker can write or modify data on the host system with the privileges of the browser process.
- The attacker can crash or disrupt the browser and potentially other processes on the host, causing service loss for the affected user.
How HarborGuard Handles This
Available on HarborGuard: images containing Google Chrome below 148.0.7778.216 are flagged as HIGH severity within minutes of CVE ingestion. A patched-image rebuild at 148.0.7778.216 is made available once the fix version is confirmed. For customers who opt into auto-remediation, HarborGuard initiates a rebuild, executes a regression test run, and opens a pull request against affected workloads; for HIGH-severity issues the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the finding is routed to the designated team inbox with the CVSS score, vector breakdown, and remediation context attached. Given that this vulnerability requires a pre-compromised renderer process, teams should also consider network-policy controls that restrict outbound connections from browser-hosting workloads as a compensating measure while rollout is in progress.
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H