HarborGuard / CVE
Back to search
HIGHCVE-2026-10017Published Modified CNA Chrome

CVE-2026-10017: Out of bounds read in Headless in Google Chrome prior to 148

Out of bounds read in Headless in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

HarborGuard Analysis

HarborGuard analysis

Synopsis

An out-of-bounds read vulnerability exists in the Headless component of Google Chrome versions prior to 148.0.7778.216. The flaw is reachable over the network but requires an attacker who has already compromised the Chrome renderer process to deliver a crafted HTML page to the victim. Successful exploitation enables a sandbox escape, giving the attacker elevated access outside the Chrome sandbox with high impact to confidentiality, integrity, and availability. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection of CVE-2026-10017 is available across every HarborGuard environment, with CVE records ingested from upstream feeds within minutes of publication and matched against all customer registry images and CI/CD pipeline images, including custom-built images derived from Chrome-based base layers.

Available
Triage

HarborGuard scores this CVE at 8.3 HIGH using the CVSS v3.1 vector, and triage routing is available per customer organization based on compliance policy weighting, directing findings to the appropriate team inbox without manual filtering.

Available
Patch

A patched-image rebuild pinned to Chrome 148.0.7778.216 is available on HarborGuard for any environment running an affected version. For customers who opt into auto-remediation, HarborGuard can trigger a rebuild, run a regression test suite, and open a pull request against affected workloads automatically, with a median time from CVE publication to merged patch PR of around 90 minutes for high-severity issues.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the target over the network, delivering a crafted HTML page to a victim running an affected Chrome version.

  • AuthenticationNot required

    No authentication or account credentials are required to stage the attack; the attacker only needs the victim to load a crafted page.

  • Victim interactionRequired

    The victim must interact with attacker-controlled content, such as visiting or being directed to a crafted HTML page, making social engineering a prerequisite.

  • Attack complexityDetail

    Attack complexity is high, meaning the attacker must have already compromised the Chrome renderer process before this vulnerability can be leveraged for a sandbox escape.

Blast Radius

  • A successful attacker escapes the Chrome sandbox and gains execution context outside its isolation boundary.
  • With high confidentiality impact, the attacker reads data accessible to the browser process, including stored credentials, session tokens, and page content from other origins.
  • With high integrity impact, the attacker modifies files, browser state, or data reachable by the browser process on the host.
  • With high availability impact, the attacker disrupts or crashes the browser process or dependent host services.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-10017 activates immediately on CVE ingestion and flags any image in a customer registry or pipeline that bundles a Chrome version below 148.0.7778.216. A rebuild at the fixed version is available for affected images. For customers who opt into auto-remediation, HarborGuard triggers the rebuild, runs regression tests, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy restricts automated changes, the finding is routed to the designated team inbox with full CVSS context and remediation guidance attached. Because this vulnerability requires a pre-compromised renderer process as a prerequisite, customers unable to patch immediately should also consider network-policy controls that restrict outbound connections from containers running Chrome-based workloads, reducing the attacker surface available to an already-compromised renderer.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H