HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-10881Published Modified CNA Chrome

CVE-2026-10881: Out of bounds read and write in ANGLE in Google Chrome prior to 149

Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Metrics

CVSS v3.1
9.6
Severity
CRITICAL
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An out-of-bounds read and write vulnerability exists in ANGLE, the graphics abstraction layer embedded in Google Chrome versions prior to 149.0.7827.53. The flaw is reachable over the network and requires no authentication, but does require a victim to visit or be redirected to a crafted HTML page. Successful exploitation enables a full sandbox escape, giving an attacker arbitrary code execution outside the Chrome renderer sandbox with high impact to confidentiality, integrity, and availability. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle or depend on Chrome or Chromium-derived components. Any image carrying a vulnerable Chrome version below 149.0.7827.53 is flagged automatically in both registry scans and CI/CD pipeline checks.

Available
Triage

HarborGuard scores this CVE at CVSS 9.6 (Critical) and surfaces it at the top of severity queues in each customer environment. Per-environment compliance policy weighting is applied, and the finding is routed to the appropriate team inbox based on each organization's configured ownership rules.

Available
Patch

A patched-image rebuild pinned to Chrome 149.0.7827.53 becomes available in HarborGuard as soon as the upstream fix is confirmed. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs regression tests against the updated image, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the victim's browser over the network by delivering or luring the victim to a crafted HTML page hosted remotely.

  • AuthenticationNot required

    No account or credential of any kind is needed to serve the malicious page and trigger the vulnerability.

  • Victim interactionRequired

    The victim must open or be redirected to a crafted HTML page, making this a social-engineering or drive-by delivery scenario.

  • Attack complexityDetail

    Exploitation is reliable and condition-free once the victim loads the page; no race condition, special memory layout, or environmental prerequisite is required.

Blast Radius

  • A successful exploit escapes the Chrome renderer sandbox, giving the attacker code execution in the context of the browser process on the victim host.
  • With sandbox escape achieved, the attacker reads arbitrary files accessible to the browser process, including stored credentials, session cookies, and user profile data.
  • The attacker writes or modifies files on the host filesystem and can persist malicious code or tamper with locally stored application data.
  • The attacker can crash or destabilize the browser process and any dependent services, causing denial of service on the affected host.

How HarborGuard Handles This

Available on HarborGuard: images containing Chrome below 149.0.7827.53 are flagged as Critical the moment the CVE record is ingested, typically within minutes of publication. For customers who opt into auto-remediation, HarborGuard queues a rebuild at the patched version 149.0.7827.53, runs a regression test suite against the rebuilt image, and opens a pull request against affected workloads; median time from CVE publication to a merged patch PR for Critical-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the flagged finding and a pre-built patched image are staged and waiting in the remediation queue. Given the sandbox-escape impact of this CVE, teams without auto-remediation enabled are advised to treat this as an emergency change and prioritize the upgrade to 149.0.7827.53 immediately.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H