HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-10891Published Modified CNA Chrome

CVE-2026-10891: Use after free in GFX in Google Chrome on Linux prior to 149

Use after free in GFX in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

Use-after-free in the GFX (graphics) component of Google Chrome on Linux, affecting all versions prior to 149.0.7827.53. The vulnerability is reachable over the network and requires no authentication, but does require a user to visit or be redirected to a crafted HTML page. Successful exploitation causes heap corruption that gives the attacker full read, write, and execution control over the affected browser process. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: CVE-2026-10891 is ingested from upstream feeds within minutes of publication and matched against all customer images in connected registries and CI pipelines, including custom-built images that bundle a Chrome or Chromium installation. No manual tagging or rule authoring is required.

Available
Triage

HarborGuard scores this CVE at 8.8 HIGH (CVSS v3.1) and weights it against each environment's compliance policy to determine urgency and routing. Findings are dispatched to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.53 is available on HarborGuard for any image found to include an affected version. For customers who have opted into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network; the target Chrome instance must be able to load an attacker-controlled or attacker-influenced HTML page via a standard HTTP/HTTPS request.

  • AuthenticationNot required

    No account, credential, or session token is needed; any anonymous network request that causes the browser to render the crafted page is sufficient.

  • Victim interactionRequired

    The targeted user must visit or be navigated to a crafted HTML page, making this a social-engineering or malicious-redirect scenario.

  • Attack complexityDetail

    Exploit reliability is high and no special environmental conditions, race conditions, or memory-layout prerequisites are required; the attack is condition-free once the page is loaded.

Blast Radius

  • Reads the contents of the browser process memory, exposing stored session tokens, credentials cached by the browser, and page content from other open tabs.
  • Writes arbitrary data into heap memory, allowing the attacker to alter application state or inject code into the running process.
  • Achieves code execution within the Chrome renderer or browser process on the affected Linux host.
  • Crashes or destabilizes the browser process, disrupting availability for the affected user session.

How HarborGuard Handles This

Available on HarborGuard: any image containing Google Chrome prior to 149.0.7827.53 is flagged immediately upon scan against CVE-2026-10891, scored at 8.8 HIGH, and surfaced with a rebuild target of 149.0.7827.53. For customers who opt into auto-remediation, HarborGuard rebuilds the image at the patched version, runs a regression test suite, and opens a pull request against the affected workload; for high-severity issues, the median time from CVE publication to a merged patch PR in environments with auto-remediation enabled is around 90 minutes. Where compliance policy requires manual approval, the finding is routed to the configured team inbox with the fix version and rebuild artifact pre-staged. Customers who manage images that embed Chrome or Chromium as part of a custom build are covered by the same pipeline, since HarborGuard matches package-level inventory inside custom images, not just base-image tags.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H