HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-10895Published Modified CNA Chrome

CVE-2026-10895: Use after free in Ozone in Google Chrome prior to 149

Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability in the Ozone graphics layer of Google Chrome (versions prior to 149.0.7827.53) allows a remote attacker to execute arbitrary code by luring a user to a crafted HTML page. The vulnerability is reachable over the network with no authentication required, but does require the victim to open a malicious page in their browser. Successful exploitation gives the attacker full code execution within the browser process. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version of Chrome.

HarborGuard Coverage

Detection

Detection capability is available across every HarborGuard environment: CVE-2026-10895 is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle a Chrome binary. Any image carrying a Chrome version below 149.0.7827.53 is flagged automatically.

Available
Triage

HarborGuard scores this CVE at 8.8 HIGH using the CVSS v3.1 vector and weights it against each environment's compliance policy, escalating findings appropriately. Triage results are routed to the inbox configured for the affected workload within each customer organization.

Available
Patch

A patched-image rebuild pinned to Chrome 149.0.7827.53 becomes available in HarborGuard the moment the fix version is resolvable from upstream package feeds. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by hosting a crafted HTML page, so the victim's browser must be able to reach attacker-controlled content on the internet or an internal network.

  • AuthenticationNot required

    No account or credential is needed on the target system; any user who visits the malicious page is at risk.

  • Victim interactionRequired

    The victim must actively open or be redirected to a crafted HTML page, requiring a social-engineering or phishing step by the attacker.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental factors.

Blast Radius

  • Attacker gains arbitrary code execution inside the Chrome renderer or browser process on the victim host.
  • Confidentiality impact is high: the attacker can read browser session tokens, saved credentials, cookies, and locally accessible files reachable by the browser process.
  • Integrity impact is high: the attacker can write or modify files and data accessible to the browser process, including cached content and profile data.
  • Availability impact is high: the attacker can crash or hang the browser process, disrupting the user's session entirely.

How HarborGuard Handles This

Available on HarborGuard: any image containing Google Chrome below 149.0.7827.53 is matched against CVE-2026-10895 within minutes of the advisory entering upstream feeds. For customers who opt into auto-remediation, HarborGuard rebuilds the affected image at Chrome 149.0.7827.53, runs a regression test pass, and opens a pull request against the affected workload. For high-severity issues, median time from CVE publication to a merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuild is staged and the PR is held open pending reviewer sign-off. Customers who do not control the Chrome version directly (for example, those consuming a vendor-supplied base image) will see the finding flagged in the registry scan and can use HarborGuard's policy controls to block deployment of unpatched images while awaiting an upstream base-image update.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H