CVE-2026-10915: Use after free in Core in Google Chrome on iOS prior to 149
Use after free in Core in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 149.0.7827.53
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A use-after-free vulnerability in the Core component of Google Chrome on iOS (versions prior to 149.0.7827.53) allows a remote attacker who has already compromised the Chrome renderer process to escape the browser sandbox via a specially crafted HTML page. The attack is delivered over the network and requires the victim to visit a malicious page, but does not require the attacker to be authenticated. Successful exploitation gives the attacker full confidentiality, integrity, and availability impact outside the sandbox boundary. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for affected environments.
HarborGuard Coverage
Detection of CVE-2026-10915 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of ingestion from upstream feeds, including custom-built images that bundle Chrome for iOS. Coverage applies to both registry scans and inline pipeline checks at build time.
AvailableHarborGuard is capable of scoring this CVE at CVSS 8.3 (High) and weighting that score against each environment's compliance policy to determine escalation priority. Triage routing is available to direct findings to the appropriate team inbox within each customer organization.
AvailableA patched-image rebuild pinned to Chrome 149.0.7827.53 becomes available in HarborGuard as soon as the upstream fix is confirmed. For customers with auto-remediation enabled, HarborGuard can perform the rebuild, run regression tests, and open a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker must reach the victim over the network, typically by hosting a crafted HTML page the victim's browser fetches remotely.
- AuthenticationNot required
No account or credential is needed on the targeted system; the attacker operates as an anonymous remote party.
- Victim interactionRequired
The victim must visit or be directed to a crafted HTML page, making social engineering or malicious ad delivery the expected delivery mechanism.
- Attack complexityDetail
Exploitation is rated High complexity, meaning the attacker must first have compromised the renderer process before this use-after-free can be leveraged for a sandbox escape, introducing a significant prerequisite condition.
Blast Radius
- A successful attacker escapes the Chrome sandbox on the iOS device, gaining code execution in a more privileged process context.
- The attacker reads data protected by the sandbox boundary, including session tokens, cookies, and locally cached content.
- The attacker can write or modify data accessible to the elevated process, tampering with stored files or application state.
- The attacker can crash or destabilize processes outside the sandbox, causing service disruption to the browser and potentially other device components.
How HarborGuard Handles This
Available on HarborGuard: detection of CVE-2026-10915 is active against all scanned images the moment the advisory is ingested, with no manual configuration required. Where images are identified as running a Chrome for iOS version below 149.0.7827.53, a rebuilt image at the patched version becomes available immediately. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, executes the configured regression-test suite, and opens a pull request against affected workloads; for high-severity issues, the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where auto-remediation is not permitted by compliance policy, the finding is routed to the appropriate team inbox with CVSS scoring and policy-weighted priority to support manual review and upgrade planning.
Fix available
- Google / Chrome< 149.0.7827.53 (from 149.0.7827.53)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H