HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-10904Published Modified CNA Chrome

CVE-2026-10904: Inappropriate implementation in V8 in Google Chrome prior to 149

Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is a sandbox-contained arbitrary code execution flaw in the V8 JavaScript engine used by Google Chrome prior to version 149.0.7827.53. The vulnerability is reachable over the network and requires no authentication, but does require a victim to visit a crafted HTML page. Successful exploitation gives an attacker arbitrary code execution within the Chrome sandbox. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle a Chrome or Chromium binary.

Available
Triage

HarborGuard scores this finding at CVSS 8.8 (High) and weights it against each environment's compliance policy to determine priority; findings are routed to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild pinned to Chrome 149.0.7827.53 is available on HarborGuard for any image found to carry an affected version. For customers with auto-remediation enabled, HarborGuard performs the rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing or luring the victim to a crafted HTML page served from a remote host.

  • AuthenticationNot required

    No account or credential of any kind is required; the attack works against any unauthenticated browser session.

  • Victim interactionRequired

    The victim must navigate to or be redirected to the attacker-controlled HTML page, making this a social-engineering or malicious-ad delivery scenario.

  • Attack complexityDetail

    Exploit complexity is low: no race conditions, memory layout dependencies, or special environmental conditions must be met for the exploit to succeed reliably.

Blast Radius

  • Attacker executes arbitrary code inside the Chrome renderer sandbox, gaining full control of the sandboxed process.
  • Confidential data processed by the browser tab (session tokens, form inputs, page content) is readable by the attacker.
  • The attacker can write or modify data within the sandbox's accessible scope, including cached credentials and local storage tied to the renderer.
  • The affected renderer process can be crashed or destabilized, disrupting the user's browser session.

How HarborGuard Handles This

Available on HarborGuard: images containing Google Chrome prior to 149.0.7827.53 are flagged automatically as soon as the CVE is ingested, typically within minutes of publication. A rebuild at the fixed version is made available for any matched image. For customers who opt into auto-remediation, HarborGuard rebuilds the image, executes the configured regression tests, and opens a pull request against affected workloads; for high-severity CVEs like this one, median time from publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where auto-remediation is not enabled or compliance policy requires manual approval, the finding appears in the HarborGuard dashboard with full CVSS context and fix-version detail so the owning team can act immediately. Because this vulnerability requires victim interaction via a browser, environments that embed Chrome as a headless or automation component should treat this as a high-priority rebuild even if direct user exposure appears limited.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H