HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-10903Published Modified CNA Chrome

CVE-2026-10903: Use after free in WebRTC in Google Chrome prior to 149

Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability in the WebRTC component of Google Chrome prior to version 149.0.7827.53 allows a remote attacker to execute arbitrary code inside the browser sandbox. The vulnerability is reachable over the network with no authentication required, but the victim must visit a crafted HTML page. Successful exploitation gives an attacker code execution within the Chrome sandbox, which combined with a sandbox escape could lead to full system compromise. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment - the CVE is matched against customer images within minutes of publication, including custom-built images that bundle Chrome or Chromium. Scans run against images in customer registries and CI/CD pipelines, flagging any image that ships a Chrome version below 149.0.7827.53.

Available
Triage

HarborGuard scores this CVE at 8.8 HIGH using the provided CVSS v3.1 vector and weighs it against each environment's compliance policy to determine urgency and routing. Findings are dispatched to the appropriate team inbox within each customer organization based on configured policy rules.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.53 becomes available on HarborGuard the moment the fix version is ingested from upstream. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by luring the victim to a crafted HTML page hosted on an attacker-controlled or compromised site.

  • AuthenticationNot required

    No account or credential is needed; any unauthenticated remote attacker can attempt the exploit.

  • Victim interactionRequired

    The victim must visit a crafted HTML page, making this a social-engineering-dependent attack that requires the attacker to direct or trick the user into opening the malicious URL.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other hard-to-control environmental factors.

Blast Radius

  • An attacker gains arbitrary code execution inside the Chrome renderer sandbox, allowing them to run attacker-controlled instructions within the browser process.
  • Confidential data processed by the browser tab (session tokens, form inputs, page content) is readable by the attacker.
  • The attacker can tamper with page content and in-browser state, enabling credential theft, session hijacking, or redirection of subsequent requests.
  • If chained with a sandbox escape, the attacker can extend control beyond the browser to the underlying host operating system.

How HarborGuard Handles This

Available on HarborGuard: detection fires within minutes of CVE publication for any image shipping Chrome below 149.0.7827.53, including internally built images that bundle Chromium. A rebuilt image at the patched version 149.0.7827.53 is made available as soon as the fix is confirmed in the upstream feed. For customers who opt into auto-remediation, HarborGuard rebuilds the image, executes a regression run, and opens a pull request against affected workloads; for HIGH-severity issues, the median time from CVE publication to merged patch PR in auto-remediation environments is around 90 minutes. Where compliance policy requires manual approval, the finding is routed to the designated team inbox with CVSS score, affected image list, and remediation diff attached for review.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H