HarborGuard / CVE
Back to search
HIGHCVE-2026-10014Published Modified CNA Chrome

CVE-2026-10014: Use after free in WebMIDI in Google Chrome on Android prior to 148

Use after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability affects the WebMIDI component of Google Chrome on Android in versions prior to 148.0.7778.216. The flaw is reachable over the network and requires no prior authentication, but the attacker must have already compromised the renderer process and must trick a victim into visiting a crafted HTML page. Successful exploitation allows a sandbox escape, giving the attacker capabilities beyond the normally restricted renderer context including full read, write, and denial-of-service impact on the affected host. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built Android or Chromium-based container images. Any image layer carrying a vulnerable Chrome version below 148.0.7778.216 is flagged automatically.

Available
Triage

HarborGuard scores this CVE at 8.3 HIGH using the published CVSS v3.1 vector and applies each customer organization's compliance policy weighting to determine urgency and priority. Findings are routed to the appropriate team inbox within each customer org based on image ownership and policy configuration.

Available
Patch

A patched-image rebuild pinned to Chrome 148.0.7778.216 becomes available through HarborGuard once the upstream fix is confirmed in the image layer. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by serving a crafted HTML page to the victim's browser, requiring the vulnerable service to be reachable over the internet or an internal network.

  • AuthenticationNot required

    No account or credential is needed; the attacker interacts with the target solely through the browser's handling of web content.

  • Victim interactionRequired

    The victim must visit a crafted HTML page, meaning the attacker must socially engineer or redirect the user to attacker-controlled content.

  • Attack complexityDetail

    Attack complexity is High, meaning the attacker must first achieve renderer process compromise before the sandbox escape becomes possible, introducing a significant precondition beyond simply serving the malicious page.

Blast Radius

  • A successful sandbox escape lets the attacker execute code outside the Chrome renderer sandbox at a higher privilege level on the Android device.
  • Confidentiality impact is High: the attacker reads data from memory regions and storage accessible to the elevated process, including session tokens and application data.
  • Integrity impact is High: the attacker writes to or modifies data and system state outside the sandbox boundary.
  • Availability impact is High: the attacker crashes or destabilizes the affected process or device, causing service disruption.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-10014 is active across all connected environments, matching images that bundle a vulnerable Chrome version against the published advisory. Because this is rated HIGH with a CVSS score of 8.3, it receives elevated triage priority in HarborGuard's scoring pipeline. A rebuild at the fixed version 148.0.7778.216 is available for images where the upstream package has been updated. For customers who opt into auto-remediation, HarborGuard performs the rebuild, executes regression tests, and opens a PR against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy does not permit automatic remediation, the finding is surfaced as a prioritized alert with remediation instructions pointing to the fixed version.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H