CVE-2026-10881: Out of bounds read and write in ANGLE in Google Chrome prior to 149
Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Metrics
- CVSS v3.1
- 9.6
- Severity
- CRITICAL
- Fixed in
- 149.0.7827.53
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An out-of-bounds read and write vulnerability exists in ANGLE, the graphics abstraction layer embedded in Google Chrome versions prior to 149.0.7827.53. The flaw is reachable over the network and requires no authentication, but does require a victim to visit or be redirected to a crafted HTML page. Successful exploitation enables a full sandbox escape, giving an attacker arbitrary code execution outside the Chrome renderer sandbox with high impact to confidentiality, integrity, and availability. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for affected environments.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle or depend on Chrome or Chromium-derived components. Any image carrying a vulnerable Chrome version below 149.0.7827.53 is flagged automatically in both registry scans and CI/CD pipeline checks.
AvailableHarborGuard scores this CVE at CVSS 9.6 (Critical) and surfaces it at the top of severity queues in each customer environment. Per-environment compliance policy weighting is applied, and the finding is routed to the appropriate team inbox based on each organization's configured ownership rules.
AvailableA patched-image rebuild pinned to Chrome 149.0.7827.53 becomes available in HarborGuard as soon as the upstream fix is confirmed. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs regression tests against the updated image, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker must reach the victim's browser over the network by delivering or luring the victim to a crafted HTML page hosted remotely.
- AuthenticationNot required
No account or credential of any kind is needed to serve the malicious page and trigger the vulnerability.
- Victim interactionRequired
The victim must open or be redirected to a crafted HTML page, making this a social-engineering or drive-by delivery scenario.
- Attack complexityDetail
Exploitation is reliable and condition-free once the victim loads the page; no race condition, special memory layout, or environmental prerequisite is required.
Blast Radius
- A successful exploit escapes the Chrome renderer sandbox, giving the attacker code execution in the context of the browser process on the victim host.
- With sandbox escape achieved, the attacker reads arbitrary files accessible to the browser process, including stored credentials, session cookies, and user profile data.
- The attacker writes or modifies files on the host filesystem and can persist malicious code or tamper with locally stored application data.
- The attacker can crash or destabilize the browser process and any dependent services, causing denial of service on the affected host.
How HarborGuard Handles This
Available on HarborGuard: images containing Chrome below 149.0.7827.53 are flagged as Critical the moment the CVE record is ingested, typically within minutes of publication. For customers who opt into auto-remediation, HarborGuard queues a rebuild at the patched version 149.0.7827.53, runs a regression test suite against the rebuilt image, and opens a pull request against affected workloads; median time from CVE publication to a merged patch PR for Critical-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the flagged finding and a pre-built patched image are staged and waiting in the remediation queue. Given the sandbox-escape impact of this CVE, teams without auto-remediation enabled are advised to treat this as an emergency change and prioritize the upgrade to 149.0.7827.53 immediately.
Fix available
- Google / Chrome< 149.0.7827.53 (from 149.0.7827.53)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H