CVE-2026-10883: Type Confusion in ANGLE in Google Chrome prior to 149
Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 149.0.7827.53
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A type confusion vulnerability in ANGLE, the graphics abstraction layer used by Google Chrome, allows a remote attacker to trigger heap corruption by directing a victim to a crafted HTML page. The vulnerability is reachable over the network and requires no authentication, though the victim must visit an attacker-controlled page. Successful exploitation gives the attacker full read, write, and crash capability over the renderer process, which in practice enables remote code execution. A patched-image rebuild at Chrome 149.0.7827.53 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Chrome or Chromium as a dependency. Any image containing a Chrome version prior to 149.0.7827.53 is flagged immediately.
AvailableHarborGuard scores this finding at CVSS 8.8 HIGH and weights it against each environment's compliance policy to determine breach-of-threshold status and urgency. Triage alerts are routed to the appropriate team inbox within the customer org based on image ownership and policy configuration.
AvailableA patched-image rebuild pinned to Chrome 149.0.7827.53 becomes available on HarborGuard for any environment where an affected image is detected. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite against the new image, and opens a pull request against the affected workload.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker must deliver the crafted HTML page to the victim over the network, so the Chrome instance must be reachable by the user via a standard internet or intranet connection.
- AuthenticationNot required
No account or credential is needed; any unauthenticated remote attacker can host the malicious page.
- Victim interactionRequired
The victim must navigate to or be redirected to the attacker-controlled HTML page, making this a social-engineering or drive-by delivery scenario.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental prerequisites.
Blast Radius
- Reads arbitrary memory within the Chrome renderer process, exposing session tokens, credentials, and page content from open tabs.
- Writes to heap memory, enabling the attacker to corrupt renderer state and pivot toward code execution within the sandboxed process.
- Crashes the renderer process, causing denial of service for the affected tab or the entire browser depending on sandbox escape success.
- If combined with a sandbox escape, gives the attacker full code execution as the OS user running Chrome.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-10883 is active across all connected registries and CI pipelines, matching images that bundle Chrome or Chromium below version 149.0.7827.53. For environments with auto-remediation enabled, HarborGuard initiates a rebuild at the fixed version, runs regression tests, and opens a PR against the affected workload; for HIGH-severity issues, median time from CVE publication to a merged patch PR is around 90 minutes in qualifying environments. Where compliance policy requires manual approval before remediation, HarborGuard surfaces the finding with full CVSS detail and ownership metadata so the responsible team can act without delay.
Fix available
- Google / Chrome< 149.0.7827.53 (from 149.0.7827.53)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H