HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-10900Published Modified CNA Chrome

CVE-2026-10900: Use after free in Passwords in Google Chrome on Mac prior to 149

Use after free in Passwords in Google Chrome on Mac prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)

Metrics

CVSS v3.1
7.5
Severity
HIGH
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability in the Passwords component of Google Chrome on macOS allows a remote attacker to corrupt heap memory. Exploitation requires luring a user into specific UI interactions on a crafted HTML page, and no authentication to the Chrome instance is needed. Successful exploitation gives the attacker full read, write, and execution-level capability over the browser process, enabling data theft, modification of in-memory state, or arbitrary code execution. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version of Chrome.

HarborGuard Coverage

Detection

Detection of CVE-2026-10900 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of ingestion from upstream feeds including the Chrome release advisory. Matching covers both public base images and custom-built images that bundle a Chrome or Chromium binary below version 149.0.7827.53.

Available
Triage

Triage is available with CVSS 7.5 HIGH scoring applied automatically, weighted further by each customer organization's compliance policy to reflect their actual exposure and risk tolerance. Findings are routed to the appropriate team inbox based on per-environment configuration, so the right engineers see the alert without manual filtering.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.53 becomes available on HarborGuard for any image found to carry an affected version. For customers who opt into auto-remediation, HarborGuard can trigger a rebuild, run regression tests against the updated image, and open a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must deliver a crafted HTML page to the victim over the network, so the Chrome instance must be reachable or the user must browse to attacker-controlled content.

  • AuthenticationNot required

    No authentication to the browser or any backing service is required; the attacker only needs the victim to visit a crafted page.

  • Victim interactionRequired

    The attacker must convince the user to perform specific UI gestures within the browser, making this a social-engineering-dependent exploit.

  • Attack complexityDetail

    Attack complexity is high, meaning the exploit depends on environmental or timing factors such as precise heap layout or race conditions that the attacker cannot fully control.

Blast Radius

  • Reads stored passwords and session tokens held in the Chrome Passwords component at the time of exploitation.
  • Modifies in-memory browser state, allowing the attacker to alter page content or intercept credentials before they are written to disk.
  • Executes arbitrary code within the Chrome renderer or browser process on the affected macOS host.
  • Crashes the affected Chrome process if heap corruption is not precisely controlled, causing a denial of service for the user.

How HarborGuard Handles This

Available on HarborGuard: images containing Google Chrome below 149.0.7827.53 on macOS base layers are flagged automatically within minutes of CVE publication. Where compliance policy permits, a rebuilt image pinned to 149.0.7827.53 is made available immediately. For customers who opt into auto-remediation, HarborGuard triggers the rebuild, runs regression tests, and opens a pull request against affected workloads; for high-severity issues, the median time from CVE publication to a merged patch PR is around 90 minutes in environments with auto-remediation enabled. Customers who manage their own patching cadence can use the HarborGuard finding to prioritize an expedited image update given the high CVSS score and the attacker's ability to achieve full compromise of the browser process with no authentication barrier.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H