CVE-2026-10013: Use after free in WebCodecs in Google Chrome prior to 148
Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
A use-after-free vulnerability in the WebCodecs component of Google Chrome prior to version 148.0.7778.216 allows a remote attacker to execute arbitrary code inside the browser sandbox by luring a victim to a crafted HTML page. The vulnerability is reachable over the network and requires no authentication, but does require the victim to visit a malicious page. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version of Chrome.
HarborGuard Coverage
Detection is available across every HarborGuard environment: CVE-2026-10013 is ingested from upstream advisory feeds within minutes of publication and matched against all customer images, including custom-built images that bundle a Chrome binary. Any image carrying a Chrome version below 148.0.7778.216 is flagged automatically.
AvailableHarborGuard scores this CVE at 8.8 HIGH using the CVSS v3.1 vector and surfaces it with per-environment compliance policy weighting to prioritize routing. Alerts are directed to the appropriate team inbox within each customer organization based on image ownership and policy configuration.
AvailableA patched-image rebuild pinned to Chrome 148.0.7778.216 becomes available on HarborGuard for any environment where an affected image is detected. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite, and opens a pull request against affected workloads; for high-severity issues the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network by directing the victim to a crafted HTML page hosted on an attacker-controlled server.
- AuthenticationNot required
No account or credential on the target system is needed; the exploit is available to any unauthenticated remote attacker.
- Victim interactionRequired
The victim must visit a crafted HTML page, meaning the attacker must socially engineer or redirect the victim to open it in a vulnerable Chrome browser.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental factors beyond the victim visiting the page.
Blast Radius
- The attacker executes arbitrary code inside the Chrome renderer sandbox, gaining control of the sandboxed process.
- With sandbox escape primitives or browser bugs chained together, the attacker reads sensitive in-browser data including session tokens, form contents, and cached credentials.
- The attacker modifies page content and intercepts or tampers with data the victim submits through the browser.
- The attacker can crash or destabilize the affected browser process, denying the victim access to browser-based services.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-10013 is active for all customer images carrying a Chrome binary below version 148.0.7778.216, including internally built images that bundle Chrome. Where a fix version is confirmed, a rebuilt image at 148.0.7778.216 is made available as soon as the upstream package is resolvable. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs regression tests, and opens a pull request against affected workloads; for high-severity CVEs like this one the median time from publication to a merged patch PR is around 90 minutes. Where compliance policy does not permit auto-remediation, the CVE appears in the findings dashboard with CVSS score, affected image list, and fix-version detail so engineering teams can action it manually.
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H