HarborGuard / CVE
Back to search
HIGHCVE-2026-10013Published Modified CNA Chrome

CVE-2026-10013: Use after free in WebCodecs in Google Chrome prior to 148

Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability in the WebCodecs component of Google Chrome prior to version 148.0.7778.216 allows a remote attacker to execute arbitrary code inside the browser sandbox by luring a victim to a crafted HTML page. The vulnerability is reachable over the network and requires no authentication, but does require the victim to visit a malicious page. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version of Chrome.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: CVE-2026-10013 is ingested from upstream advisory feeds within minutes of publication and matched against all customer images, including custom-built images that bundle a Chrome binary. Any image carrying a Chrome version below 148.0.7778.216 is flagged automatically.

Available
Triage

HarborGuard scores this CVE at 8.8 HIGH using the CVSS v3.1 vector and surfaces it with per-environment compliance policy weighting to prioritize routing. Alerts are directed to the appropriate team inbox within each customer organization based on image ownership and policy configuration.

Available
Patch

A patched-image rebuild pinned to Chrome 148.0.7778.216 becomes available on HarborGuard for any environment where an affected image is detected. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite, and opens a pull request against affected workloads; for high-severity issues the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing the victim to a crafted HTML page hosted on an attacker-controlled server.

  • AuthenticationNot required

    No account or credential on the target system is needed; the exploit is available to any unauthenticated remote attacker.

  • Victim interactionRequired

    The victim must visit a crafted HTML page, meaning the attacker must socially engineer or redirect the victim to open it in a vulnerable Chrome browser.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental factors beyond the victim visiting the page.

Blast Radius

  • The attacker executes arbitrary code inside the Chrome renderer sandbox, gaining control of the sandboxed process.
  • With sandbox escape primitives or browser bugs chained together, the attacker reads sensitive in-browser data including session tokens, form contents, and cached credentials.
  • The attacker modifies page content and intercepts or tampers with data the victim submits through the browser.
  • The attacker can crash or destabilize the affected browser process, denying the victim access to browser-based services.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-10013 is active for all customer images carrying a Chrome binary below version 148.0.7778.216, including internally built images that bundle Chrome. Where a fix version is confirmed, a rebuilt image at 148.0.7778.216 is made available as soon as the upstream package is resolvable. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs regression tests, and opens a pull request against affected workloads; for high-severity CVEs like this one the median time from publication to a merged patch PR is around 90 minutes. Where compliance policy does not permit auto-remediation, the CVE appears in the findings dashboard with CVSS score, affected image list, and fix-version detail so engineering teams can action it manually.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H