CVE-2026-10939: Use after free in WebRTC in Google Chrome prior to 149
Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 149.0.7827.53
- Affected Products
- 1
HarborGuard Analysis
Synopsis
Use-after-free in the WebRTC component of Google Chrome (versions prior to 149.0.7827.53) allows a remote attacker to execute arbitrary code inside the browser sandbox by luring a user to a crafted HTML page. The vulnerability is reachable over the network and requires no authentication, but does require the victim to visit a malicious page. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version of Chrome.
HarborGuard Coverage
Detection for CVE-2026-10939 is available across every HarborGuard environment, with the CVE ingested from upstream feeds and matched against customer images within minutes of publication, including custom-built images that bundle a Chrome or Chromium binary. Any image carrying a Chrome version below 149.0.7827.53 is flagged automatically.
AvailableHarborGuard scores this CVE at 8.8 HIGH using the published CVSS v3.1 vector and weights findings against each customer organization's compliance policy to determine urgency and routing. Alerts are directed to the appropriate team inbox within each customer environment based on configured ownership rules.
AvailableA patched-image rebuild at Chrome 149.0.7827.53 is available on HarborGuard for any image found to carry an affected version. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite, and opens a pull request against the affected workload automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network; the target Chrome instance must be able to reach an attacker-controlled URL.
- AuthenticationNot required
No account or credential of any kind is needed; any unauthenticated user who visits the page is exposed.
- Victim interactionRequired
The victim must navigate to or be redirected to a crafted HTML page, making this a social-engineering-dependent attack.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, memory layout luck, or other environmental factors.
Blast Radius
- A successful attacker executes arbitrary code within the Chrome renderer sandbox, gaining full control over the renderer process.
- Confidentiality impact is high: the attacker can read data accessible to the renderer, including page content, stored credentials surfaced by autofill, and session tokens.
- Integrity impact is high: the attacker can modify page content and data written through the renderer, including form submissions and local storage.
- Availability impact is high: the attacker can crash or hang the affected browser process, disrupting the user session.
How HarborGuard Handles This
Available on HarborGuard: any image bundling Google Chrome below 149.0.7827.53 is detected within minutes of the CVE entering upstream feeds. A rebuild at the fixed version (149.0.7827.53) is available for affected images. For customers who opt into auto-remediation, HarborGuard triggers the rebuild, runs regression tests, and opens a pull request against affected workloads; for high-severity CVEs, the median time from publication to a merged patch PR in auto-remediation environments is around 90 minutes. Where compliance policy does not permit auto-remediation, findings are routed to the configured team inbox with full CVSS context so engineers can act manually. Because this vulnerability requires victim interaction rather than purely passive exposure, teams should also consider network-policy controls that restrict which internal hosts can load arbitrary external URLs via Chrome-based tooling while a patch is being rolled out.
Fix available
- Google / Chrome< 149.0.7827.53 (from 149.0.7827.53)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H