HarborGuard / CVE
Back to search
HIGHCVE-2026-10021Published Modified CNA Chrome

CVE-2026-10021: Insufficient validation of untrusted input in USB in Google Chrome prior to 148

Insufficient validation of untrusted input in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)

HarborGuard Analysis

HarborGuard analysis

Synopsis

Insufficient input validation in the USB handling component of Google Chrome (versions prior to 148.0.7778.216) allows a remote attacker to execute arbitrary code. The attack is reachable over the network but requires the victim to visit a crafted HTML page; no authentication or account is needed on the attacker's side. Successful exploitation gives the attacker full code execution in the context of the browser process, with high impact on confidentiality, integrity, and availability. A patched-image rebuild at 148.0.7778.216 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment - CVE-2026-10021 is ingested from upstream advisory feeds within minutes of publication and matched against all customer images, including custom-built images that bundle a Chromium or Chrome runtime. Any image in a customer registry or CI pipeline running a Chrome version below 148.0.7778.216 is flagged automatically.

Available
Triage

HarborGuard scores this finding at CVSS 8.8 (HIGH) and weights it against each environment's compliance policy to determine urgency and routing. The resulting alert is directed to the appropriate team inbox within each customer organization based on their configured ownership rules.

Available
Patch

A patched-image rebuild at Chrome 148.0.7778.216 becomes available on HarborGuard the moment the upstream fix version is confirmed. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing the victim to a crafted HTML page, so the Chrome instance must be reachable from or navigable to an attacker-controlled origin.

  • AuthenticationNot required

    No account or credentials on any system are required; the attacker only needs to serve a malicious page to the victim.

  • Victim interactionRequired

    The victim must visit (or be redirected to) the attacker-crafted HTML page, making this a social-engineering or drive-by-navigation attack.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and imposes no special timing constraints, race conditions, or environmental prerequisites beyond getting the victim to load the page.

Blast Radius

  • A successful attacker achieves arbitrary code execution inside the Chrome browser process on the victim's machine.
  • With high confidentiality impact, the attacker can read browser-stored data including cookies, saved passwords, and session tokens.
  • With high integrity impact, the attacker can write or modify files and data accessible to the browser process.
  • With high availability impact, the attacker can crash or otherwise disable the browser, disrupting the user's session and any browser-dependent workflows.

How HarborGuard Handles This

Available on HarborGuard: any image in a customer registry or pipeline that includes a Chrome or Chromium binary below 148.0.7778.216 is flagged against this CVE within minutes of the advisory being ingested. For customers with auto-remediation enabled, HarborGuard rebuilds the affected image at the patched version, runs regression tests, and opens a PR against the affected workload - median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual review before merging, the PR and full finding detail are routed to the designated team inbox for approval. Customers who cannot immediately update are encouraged to apply network-policy controls that restrict which origins browser-based workloads can reach, reducing the surface for drive-by navigation attacks.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H