CVE-2026-10932: Use after free in UI in Google Chrome on Android prior to 149
Use after free in UI in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 149.0.7827.53
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A use-after-free vulnerability affects Google Chrome on Android in versions prior to 149.0.7827.53. The flaw is reachable over the network with no authentication required, but the victim must visit a crafted HTML page that the attacker controls or has injected content into. Successful exploitation causes heap corruption and gives the attacker full read, write, and crash capabilities within the browser process. A patched-image rebuild at 149.0.7827.53 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built Android-based container images that bundle a Chrome binary.
AvailableHarborGuard scores this finding at CVSS 8.8 (HIGH) and weights it against each environment's compliance policy to determine urgency and routing, sending the alert to the team or inbox configured for that workload inside each customer organization.
AvailableA patched-image rebuild pinned to Chrome 149.0.7827.53 becomes available on HarborGuard the moment the fix version is confirmed in the advisory. For customers who opt into auto-remediation, HarborGuard runs a rebuild, executes a regression test suite, and opens a PR against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network by directing or redirecting the victim to a crafted HTML page hosted on an attacker-controlled origin.
- AuthenticationNot required
No account or credential of any kind is required; any anonymous network request that reaches the victim's browser is sufficient to deliver the payload.
- Victim interactionRequired
The victim must open or be redirected to the attacker's crafted HTML page in Chrome on Android, making this a social-engineering or malicious-ad delivery scenario.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental preconditions.
Blast Radius
- The attacker reads memory contents of the Chrome browser process, including stored session tokens, cookies, and in-page credentials.
- The attacker writes to heap memory, enabling modification of browser state and potentially pivoting to further exploitation of the renderer or OS sandbox.
- The attacker can crash the Chrome browser process, disrupting the user's session and any active web application relying on it.
- All three impacts (confidentiality, integrity, and availability) are rated HIGH in the CVSS vector, so the attacker gains the full range of capabilities without partial limitations.
How HarborGuard Handles This
Available on HarborGuard: images containing a Chrome binary below 149.0.7827.53 are flagged automatically as soon as the CVE is ingested. For customers who opt into auto-remediation, HarborGuard rebuilds the image at the patched version, runs regression tests, and opens a PR against affected workloads; the median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the finding is routed to the designated team inbox with CVSS score, vector breakdown, and a direct link to the upstream fix. Customers who cannot immediately update should consider network-policy controls that restrict the Chrome-based service's inbound HTML sources, or feature-flag gating that disables the affected UI surface until the patched image is deployed.
Fix available
- Google / Chrome< 149.0.7827.53 (from 149.0.7827.53)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H