HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-10932Published Modified CNA Chrome

CVE-2026-10932: Use after free in UI in Google Chrome on Android prior to 149

Use after free in UI in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability affects Google Chrome on Android in versions prior to 149.0.7827.53. The flaw is reachable over the network with no authentication required, but the victim must visit a crafted HTML page that the attacker controls or has injected content into. Successful exploitation causes heap corruption and gives the attacker full read, write, and crash capabilities within the browser process. A patched-image rebuild at 149.0.7827.53 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built Android-based container images that bundle a Chrome binary.

Available
Triage

HarborGuard scores this finding at CVSS 8.8 (HIGH) and weights it against each environment's compliance policy to determine urgency and routing, sending the alert to the team or inbox configured for that workload inside each customer organization.

Available
Patch

A patched-image rebuild pinned to Chrome 149.0.7827.53 becomes available on HarborGuard the moment the fix version is confirmed in the advisory. For customers who opt into auto-remediation, HarborGuard runs a rebuild, executes a regression test suite, and opens a PR against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing or redirecting the victim to a crafted HTML page hosted on an attacker-controlled origin.

  • AuthenticationNot required

    No account or credential of any kind is required; any anonymous network request that reaches the victim's browser is sufficient to deliver the payload.

  • Victim interactionRequired

    The victim must open or be redirected to the attacker's crafted HTML page in Chrome on Android, making this a social-engineering or malicious-ad delivery scenario.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental preconditions.

Blast Radius

  • The attacker reads memory contents of the Chrome browser process, including stored session tokens, cookies, and in-page credentials.
  • The attacker writes to heap memory, enabling modification of browser state and potentially pivoting to further exploitation of the renderer or OS sandbox.
  • The attacker can crash the Chrome browser process, disrupting the user's session and any active web application relying on it.
  • All three impacts (confidentiality, integrity, and availability) are rated HIGH in the CVSS vector, so the attacker gains the full range of capabilities without partial limitations.

How HarborGuard Handles This

Available on HarborGuard: images containing a Chrome binary below 149.0.7827.53 are flagged automatically as soon as the CVE is ingested. For customers who opt into auto-remediation, HarborGuard rebuilds the image at the patched version, runs regression tests, and opens a PR against affected workloads; the median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the finding is routed to the designated team inbox with CVSS score, vector breakdown, and a direct link to the upstream fix. Customers who cannot immediately update should consider network-policy controls that restrict the Chrome-based service's inbound HTML sources, or feature-flag gating that disables the affected UI surface until the patched image is deployed.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H