CVE-2026-10886: Use after free in FileSystem in Google Chrome prior to 149
Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Metrics
- CVSS v3.1
- 9.6
- Severity
- CRITICAL
- Fixed in
- 149.0.7827.53
- Affected Products
- 1
HarborGuard Analysis
Synopsis
Use-after-free in the FileSystem component of Google Chrome prior to version 149.0.7827.53 allows a remote attacker to exploit freed memory by luring a victim to a crafted HTML page. The vulnerability is reachable over the network and requires no authentication, though the victim must visit an attacker-controlled page. Successful exploitation enables a sandbox escape, giving the attacker full read, write, and availability impact beyond Chrome's sandboxed environment. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle a Chrome or Chromium runtime.
AvailableHarborGuard scores this CVE at 9.6 CRITICAL using the published CVSS v3.1 vector and weights findings against each customer environment's compliance policy, then routes alerts to the appropriate team inbox within that organization.
AvailableA patched-image rebuild at Chrome 149.0.7827.53 becomes available on HarborGuard for any environment running an affected version. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite, and opens a PR against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network by directing the victim to a crafted HTML page hosted on an attacker-controlled server.
- AuthenticationNot required
No account or credentials are needed on the targeted system; any anonymous visitor can be targeted.
- Victim interactionRequired
The victim must visit the attacker-controlled HTML page, requiring a social-engineering step such as a phishing link or malicious ad.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental preconditions.
Blast Radius
- The attacker escapes Chrome's sandbox, gaining code execution in the context of the browser process on the victim host.
- Confidential data accessible to the browser process, including stored credentials, cookies, and session tokens, is readable by the attacker.
- The attacker can write to or modify files and data accessible to the browser process, including persistent browser state.
- The browser process and any dependent services can be crashed or disrupted, causing a denial of service for the affected user.
How HarborGuard Handles This
Available on HarborGuard: images containing a Chrome or Chromium runtime below version 149.0.7827.53 are flagged as CRITICAL within minutes of CVE ingestion. For customers with auto-remediation enabled, HarborGuard rebuilds the affected image at the patched version, runs regression tests, and opens a PR against affected workloads; median time from CVE publication to merged patch PR for critical-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual review, the finding is routed to the responsible team with CVSS context and remediation guidance attached. Because this vulnerability requires victim interaction via a crafted page, customers who cannot immediately patch are advised to enforce network policies that restrict outbound browser access to untrusted origins and to consider disabling affected FileSystem API surface through feature-flag configuration where supported.
Fix available
- Google / Chrome< 149.0.7827.53 (from 149.0.7827.53)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H