CVE-2026-10016: Use after free in DOM in Google Chrome prior to 148
Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
A use-after-free vulnerability in the DOM engine of Google Chrome prior to version 148.0.7778.216 allows a remote attacker to execute arbitrary code inside the browser sandbox by luring a user to a crafted HTML page. The flaw is reachable over the network and requires no authentication, only a single user interaction (visiting a malicious page). Successful exploitation gives the attacker arbitrary code execution within the Chrome sandbox, enabling data theft, further exploitation, and potential sandbox escapes. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection of CVE-2026-10016 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of ingestion from upstream feeds, including custom-built images that bundle or pin a Chrome version below 148.0.7778.216. Coverage applies to images in both connected registries and active CI/CD pipelines.
AvailableTriage is available with automatic CVSS v3.1 scoring applied at detection time, surfacing this issue at a score of 8.8 (HIGH). Per-environment compliance policy weighting and team-routing rules direct the finding to the appropriate inbox within each customer organization.
AvailableA patched-image rebuild pinned to Chrome 148.0.7778.216 becomes available on HarborGuard the moment the fix version is confirmed against the affected image layer. For customers who opt into auto-remediation, the pipeline performs the rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network; the target must be able to reach an attacker-controlled HTML page from their browser.
- AuthenticationNot required
No account, session token, or credential of any kind is needed; the exploit works against any unauthenticated visitor.
- Victim interactionRequired
The victim must visit a crafted HTML page, making this a social-engineering vector (phishing link, malicious ad, or compromised site).
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and requires no special race conditions or environmental preconditions to trigger.
Blast Radius
- Arbitrary code executes inside the Chrome renderer sandbox, giving the attacker full control of the sandboxed process.
- The attacker reads any data accessible to the renderer, including session tokens, form contents, and page DOM state for the active origin.
- The attacker can write or tamper with page content and in-memory state within the sandboxed context.
- A successful sandbox escape (chained with a secondary bug) would extend execution to the host user account and its files.
How HarborGuard Handles This
Available on HarborGuard: images containing a Chrome version below 148.0.7778.216 are flagged automatically within minutes of CVE publication, with no manual feed configuration required. A patched rebuild targeting version 148.0.7778.216 is made available as soon as the fix version is matched against the affected image layer. For customers who opt into auto-remediation, HarborGuard performs the rebuild, executes the configured regression tests, and opens a pull request against affected workloads; median time from CVE publication to a merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Customers who manage remediation manually will find the finding routed to the correct team inbox based on their compliance policy configuration, along with the pinned fix version and affected layer details needed to act immediately.
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H