CVE-2026-10938: Inappropriate implementation in Input in Google Chrome prior to 149
Inappropriate implementation in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Metrics
- CVSS v3.1
- 8.1
- Severity
- HIGH
- Fixed in
- 149.0.7827.53
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An inappropriate implementation flaw in the Input handling component of Google Chrome prior to version 149.0.7827.53 allows a remote attacker who has already compromised the renderer process to bypass site isolation. The attack is reachable over the network and requires no authentication, though a victim must interact with a crafted HTML page. Successful exploitation grants the attacker unauthorized read access to sensitive cross-site data and the ability to tamper with cross-origin content. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for affected environments.
HarborGuard Coverage
Detection of CVE-2026-10938 is available across every HarborGuard environment, with the CVE matched against customer images, including custom-built images, within minutes of ingestion from upstream advisory feeds. Any image containing a Chrome version below 149.0.7827.53 in a customer registry or CI pipeline is flagged automatically.
AvailableHarborGuard is capable of scoring this CVE at CVSS 8.1 (High) and weighting it against each environment's compliance policy to determine urgency. Triage routing delivers findings to the appropriate team inbox within each customer organization based on configured ownership rules.
AvailableA patched-image rebuild at Chrome 149.0.7827.53 becomes available through HarborGuard once the fix version is confirmed in the upstream feed. For customers who opt into auto-remediation, HarborGuard can perform the rebuild, run a regression test suite, and open a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the crafted HTML page over the network, requiring the victim's browser to reach an attacker-controlled or compromised remote resource.
- AuthenticationNot required
No account credentials or prior authentication are needed; the attack is reachable by any unauthenticated remote party.
- Victim interactionRequired
The victim must visit or be directed to a crafted HTML page, making this a social-engineering or drive-by delivery scenario.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layout, or other variable environmental factors, though a prior renderer compromise is a prerequisite condition.
Blast Radius
- Reads cross-origin data from other sites loaded in the browser, such as session tokens, page content, or stored credentials, by bypassing site isolation boundaries.
- Modifies or injects content into cross-origin contexts, enabling tampering with data the victim exchanges with other sites.
- The attack is scoped to the browser process and does not directly affect system availability; no denial-of-service or crash impact is expected based on the CVSS vector.
How HarborGuard Handles This
Available on HarborGuard: detection for this CVE is matched against all scanned images the moment the advisory is ingested, covering both registry images and images built in CI pipelines. For environments running Chrome below 149.0.7827.53, a rebuilt image at the patched version is available. Where compliance policy permits auto-remediation, HarborGuard can rebuild the image, execute regression tests, and open a pull request against affected workloads; for high-severity issues, the median time from CVE publication to merged patch PR in environments with auto-remediation enabled is around 90 minutes. Teams that require manual approval before merging will receive the pull request and regression results in their configured inbox for review. Because this vulnerability requires a prior renderer compromise, teams may also consider applying network policy controls to restrict outbound connections from browser-hosting workloads as a compensating control while rollout proceeds.
Fix available
- Google / Chrome< 149.0.7827.53 (from 149.0.7827.53)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N