CVE-2026-10895: Use after free in Ozone in Google Chrome prior to 149
Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 149.0.7827.53
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A use-after-free vulnerability in the Ozone graphics layer of Google Chrome (versions prior to 149.0.7827.53) allows a remote attacker to execute arbitrary code by luring a user to a crafted HTML page. The vulnerability is reachable over the network with no authentication required, but does require the victim to open a malicious page in their browser. Successful exploitation gives the attacker full code execution within the browser process. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version of Chrome.
HarborGuard Coverage
Detection capability is available across every HarborGuard environment: CVE-2026-10895 is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle a Chrome binary. Any image carrying a Chrome version below 149.0.7827.53 is flagged automatically.
AvailableHarborGuard scores this CVE at 8.8 HIGH using the CVSS v3.1 vector and weights it against each environment's compliance policy, escalating findings appropriately. Triage results are routed to the inbox configured for the affected workload within each customer organization.
AvailableA patched-image rebuild pinned to Chrome 149.0.7827.53 becomes available in HarborGuard the moment the fix version is resolvable from upstream package feeds. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network by hosting a crafted HTML page, so the victim's browser must be able to reach attacker-controlled content on the internet or an internal network.
- AuthenticationNot required
No account or credential is needed on the target system; any user who visits the malicious page is at risk.
- Victim interactionRequired
The victim must actively open or be redirected to a crafted HTML page, requiring a social-engineering or phishing step by the attacker.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental factors.
Blast Radius
- Attacker gains arbitrary code execution inside the Chrome renderer or browser process on the victim host.
- Confidentiality impact is high: the attacker can read browser session tokens, saved credentials, cookies, and locally accessible files reachable by the browser process.
- Integrity impact is high: the attacker can write or modify files and data accessible to the browser process, including cached content and profile data.
- Availability impact is high: the attacker can crash or hang the browser process, disrupting the user's session entirely.
How HarborGuard Handles This
Available on HarborGuard: any image containing Google Chrome below 149.0.7827.53 is matched against CVE-2026-10895 within minutes of the advisory entering upstream feeds. For customers who opt into auto-remediation, HarborGuard rebuilds the affected image at Chrome 149.0.7827.53, runs a regression test pass, and opens a pull request against the affected workload. For high-severity issues, median time from CVE publication to a merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuild is staged and the PR is held open pending reviewer sign-off. Customers who do not control the Chrome version directly (for example, those consuming a vendor-supplied base image) will see the finding flagged in the registry scan and can use HarborGuard's policy controls to block deployment of unpatched images while awaiting an upstream base-image update.
Fix available
- Google / Chrome< 149.0.7827.53 (from 149.0.7827.53)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H