HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-10929Published Modified CNA Chrome

CVE-2026-10929: Heap buffer overflow in ANGLE in Google Chrome on Android prior to 149

Heap buffer overflow in ANGLE in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A heap buffer overflow vulnerability exists in ANGLE, the graphics translation layer used by Google Chrome on Android, in versions prior to 149.0.7827.53. The vulnerability is reachable over the network and requires no authentication, but does require the attacker to have already compromised the Chrome renderer process and to trick the victim into visiting a crafted HTML page. Successful exploitation allows the attacker to escape the browser sandbox, gaining elevated access beyond the sandboxed renderer with high impact to confidentiality, integrity, and availability. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that package Chrome or Android-based browser runtimes.

Available
Triage

HarborGuard scores this CVE at 8.3 HIGH using the CVSS v3.1 vector and is capable of weighting that score against per-environment compliance policies before routing alerts to the appropriate team inbox within each customer organization.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.53 is available on HarborGuard for any environment where an affected image is detected. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the victim over the network by delivering a crafted HTML page, making this an over-the-network exposure.

  • AuthenticationNot required

    No authentication or account credentials are needed to initiate the attack against the target.

  • Victim interactionRequired

    The victim must visit or be directed to a crafted HTML page, requiring a social-engineering or phishing step.

  • Attack complexityDetail

    Exploitation is rated High complexity because the attacker must first have compromised the renderer process before leveraging this overflow, introducing a significant pre-condition.

Blast Radius

  • Attacker escapes the Chrome sandbox, breaking out of the isolation boundary meant to contain compromised renderer code.
  • Reads sensitive data accessible to the browser process, including stored credentials, session tokens, and page content from other origins.
  • Modifies browser state, local storage, or data accessible at the elevated post-sandbox-escape privilege level.
  • Crashes or destabilizes the browser process, causing denial of service to the affected user session.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-10929 is active across all connected environments, matching any image that packages a Chrome version below 149.0.7827.53 on Android. A patched-image rebuild at 149.0.7827.53 is available the moment an affected image is identified. For customers who opt into auto-remediation, HarborGuard performs the rebuild, executes a regression run, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy does not permit auto-remediation, HarborGuard surfaces the finding with full CVSS context and routes it to the configured owner for manual review and promotion of the patched image.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H