CVE-2026-10929: Heap buffer overflow in ANGLE in Google Chrome on Android prior to 149
Heap buffer overflow in ANGLE in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 149.0.7827.53
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A heap buffer overflow vulnerability exists in ANGLE, the graphics translation layer used by Google Chrome on Android, in versions prior to 149.0.7827.53. The vulnerability is reachable over the network and requires no authentication, but does require the attacker to have already compromised the Chrome renderer process and to trick the victim into visiting a crafted HTML page. Successful exploitation allows the attacker to escape the browser sandbox, gaining elevated access beyond the sandboxed renderer with high impact to confidentiality, integrity, and availability. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that package Chrome or Android-based browser runtimes.
AvailableHarborGuard scores this CVE at 8.3 HIGH using the CVSS v3.1 vector and is capable of weighting that score against per-environment compliance policies before routing alerts to the appropriate team inbox within each customer organization.
AvailableA patched-image rebuild at Chrome 149.0.7827.53 is available on HarborGuard for any environment where an affected image is detected. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker must reach the victim over the network by delivering a crafted HTML page, making this an over-the-network exposure.
- AuthenticationNot required
No authentication or account credentials are needed to initiate the attack against the target.
- Victim interactionRequired
The victim must visit or be directed to a crafted HTML page, requiring a social-engineering or phishing step.
- Attack complexityDetail
Exploitation is rated High complexity because the attacker must first have compromised the renderer process before leveraging this overflow, introducing a significant pre-condition.
Blast Radius
- Attacker escapes the Chrome sandbox, breaking out of the isolation boundary meant to contain compromised renderer code.
- Reads sensitive data accessible to the browser process, including stored credentials, session tokens, and page content from other origins.
- Modifies browser state, local storage, or data accessible at the elevated post-sandbox-escape privilege level.
- Crashes or destabilizes the browser process, causing denial of service to the affected user session.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-10929 is active across all connected environments, matching any image that packages a Chrome version below 149.0.7827.53 on Android. A patched-image rebuild at 149.0.7827.53 is available the moment an affected image is identified. For customers who opt into auto-remediation, HarborGuard performs the rebuild, executes a regression run, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy does not permit auto-remediation, HarborGuard surfaces the finding with full CVSS context and routes it to the configured owner for manual review and promotion of the patched image.
Fix available
- Google / Chrome< 149.0.7827.53 (from 149.0.7827.53)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H