HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-10938Published Modified CNA Chrome

CVE-2026-10938: Inappropriate implementation in Input in Google Chrome prior to 149

Inappropriate implementation in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.1
Severity
HIGH
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An inappropriate implementation flaw in the Input handling component of Google Chrome prior to version 149.0.7827.53 allows a remote attacker who has already compromised the renderer process to bypass site isolation. The attack is reachable over the network and requires no authentication, though a victim must interact with a crafted HTML page. Successful exploitation grants the attacker unauthorized read access to sensitive cross-site data and the ability to tamper with cross-origin content. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection of CVE-2026-10938 is available across every HarborGuard environment, with the CVE matched against customer images, including custom-built images, within minutes of ingestion from upstream advisory feeds. Any image containing a Chrome version below 149.0.7827.53 in a customer registry or CI pipeline is flagged automatically.

Available
Triage

HarborGuard is capable of scoring this CVE at CVSS 8.1 (High) and weighting it against each environment's compliance policy to determine urgency. Triage routing delivers findings to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.53 becomes available through HarborGuard once the fix version is confirmed in the upstream feed. For customers who opt into auto-remediation, HarborGuard can perform the rebuild, run a regression test suite, and open a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the crafted HTML page over the network, requiring the victim's browser to reach an attacker-controlled or compromised remote resource.

  • AuthenticationNot required

    No account credentials or prior authentication are needed; the attack is reachable by any unauthenticated remote party.

  • Victim interactionRequired

    The victim must visit or be directed to a crafted HTML page, making this a social-engineering or drive-by delivery scenario.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layout, or other variable environmental factors, though a prior renderer compromise is a prerequisite condition.

Blast Radius

  • Reads cross-origin data from other sites loaded in the browser, such as session tokens, page content, or stored credentials, by bypassing site isolation boundaries.
  • Modifies or injects content into cross-origin contexts, enabling tampering with data the victim exchanges with other sites.
  • The attack is scoped to the browser process and does not directly affect system availability; no denial-of-service or crash impact is expected based on the CVSS vector.

How HarborGuard Handles This

Available on HarborGuard: detection for this CVE is matched against all scanned images the moment the advisory is ingested, covering both registry images and images built in CI pipelines. For environments running Chrome below 149.0.7827.53, a rebuilt image at the patched version is available. Where compliance policy permits auto-remediation, HarborGuard can rebuild the image, execute regression tests, and open a pull request against affected workloads; for high-severity issues, the median time from CVE publication to merged patch PR in environments with auto-remediation enabled is around 90 minutes. Teams that require manual approval before merging will receive the pull request and regression results in their configured inbox for review. Because this vulnerability requires a prior renderer compromise, teams may also consider applying network policy controls to restrict outbound connections from browser-hosting workloads as a compensating control while rollout proceeds.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N