CVE-2026-10014: Use after free in WebMIDI in Google Chrome on Android prior to 148
Use after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
A use-after-free vulnerability affects the WebMIDI component of Google Chrome on Android in versions prior to 148.0.7778.216. The flaw is reachable over the network and requires no prior authentication, but the attacker must have already compromised the renderer process and must trick a victim into visiting a crafted HTML page. Successful exploitation allows a sandbox escape, giving the attacker capabilities beyond the normally restricted renderer context including full read, write, and denial-of-service impact on the affected host. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built Android or Chromium-based container images. Any image layer carrying a vulnerable Chrome version below 148.0.7778.216 is flagged automatically.
AvailableHarborGuard scores this CVE at 8.3 HIGH using the published CVSS v3.1 vector and applies each customer organization's compliance policy weighting to determine urgency and priority. Findings are routed to the appropriate team inbox within each customer org based on image ownership and policy configuration.
AvailableA patched-image rebuild pinned to Chrome 148.0.7778.216 becomes available through HarborGuard once the upstream fix is confirmed in the image layer. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network by serving a crafted HTML page to the victim's browser, requiring the vulnerable service to be reachable over the internet or an internal network.
- AuthenticationNot required
No account or credential is needed; the attacker interacts with the target solely through the browser's handling of web content.
- Victim interactionRequired
The victim must visit a crafted HTML page, meaning the attacker must socially engineer or redirect the user to attacker-controlled content.
- Attack complexityDetail
Attack complexity is High, meaning the attacker must first achieve renderer process compromise before the sandbox escape becomes possible, introducing a significant precondition beyond simply serving the malicious page.
Blast Radius
- A successful sandbox escape lets the attacker execute code outside the Chrome renderer sandbox at a higher privilege level on the Android device.
- Confidentiality impact is High: the attacker reads data from memory regions and storage accessible to the elevated process, including session tokens and application data.
- Integrity impact is High: the attacker writes to or modifies data and system state outside the sandbox boundary.
- Availability impact is High: the attacker crashes or destabilizes the affected process or device, causing service disruption.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-10014 is active across all connected environments, matching images that bundle a vulnerable Chrome version against the published advisory. Because this is rated HIGH with a CVSS score of 8.3, it receives elevated triage priority in HarborGuard's scoring pipeline. A rebuild at the fixed version 148.0.7778.216 is available for images where the upstream package has been updated. For customers who opt into auto-remediation, HarborGuard performs the rebuild, executes regression tests, and opens a PR against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy does not permit automatic remediation, the finding is surfaced as a prioritized alert with remediation instructions pointing to the fixed version.
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H