HarborGuard / CVE
Back to search
HIGHCVE-2026-10016Published Modified CNA Chrome

CVE-2026-10016: Use after free in DOM in Google Chrome prior to 148

Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability in the DOM engine of Google Chrome prior to version 148.0.7778.216 allows a remote attacker to execute arbitrary code inside the browser sandbox by luring a user to a crafted HTML page. The flaw is reachable over the network and requires no authentication, only a single user interaction (visiting a malicious page). Successful exploitation gives the attacker arbitrary code execution within the Chrome sandbox, enabling data theft, further exploitation, and potential sandbox escapes. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-10016 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of ingestion from upstream feeds, including custom-built images that bundle or pin a Chrome version below 148.0.7778.216. Coverage applies to images in both connected registries and active CI/CD pipelines.

Available
Triage

Triage is available with automatic CVSS v3.1 scoring applied at detection time, surfacing this issue at a score of 8.8 (HIGH). Per-environment compliance policy weighting and team-routing rules direct the finding to the appropriate inbox within each customer organization.

Available
Patch

A patched-image rebuild pinned to Chrome 148.0.7778.216 becomes available on HarborGuard the moment the fix version is confirmed against the affected image layer. For customers who opt into auto-remediation, the pipeline performs the rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network; the target must be able to reach an attacker-controlled HTML page from their browser.

  • AuthenticationNot required

    No account, session token, or credential of any kind is needed; the exploit works against any unauthenticated visitor.

  • Victim interactionRequired

    The victim must visit a crafted HTML page, making this a social-engineering vector (phishing link, malicious ad, or compromised site).

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and requires no special race conditions or environmental preconditions to trigger.

Blast Radius

  • Arbitrary code executes inside the Chrome renderer sandbox, giving the attacker full control of the sandboxed process.
  • The attacker reads any data accessible to the renderer, including session tokens, form contents, and page DOM state for the active origin.
  • The attacker can write or tamper with page content and in-memory state within the sandboxed context.
  • A successful sandbox escape (chained with a secondary bug) would extend execution to the host user account and its files.

How HarborGuard Handles This

Available on HarborGuard: images containing a Chrome version below 148.0.7778.216 are flagged automatically within minutes of CVE publication, with no manual feed configuration required. A patched rebuild targeting version 148.0.7778.216 is made available as soon as the fix version is matched against the affected image layer. For customers who opt into auto-remediation, HarborGuard performs the rebuild, executes the configured regression tests, and opens a pull request against affected workloads; median time from CVE publication to a merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Customers who manage remediation manually will find the finding routed to the correct team inbox based on their compliance policy configuration, along with the pinned fix version and affected layer details needed to act immediately.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H