HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-10941Published Modified CNA Chrome

CVE-2026-10941: Out of bounds memory access in Skia in Google Chrome prior to 149

Out of bounds memory access in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An out-of-bounds memory access vulnerability exists in Skia, the graphics rendering library embedded in Google Chrome versions prior to 149.0.7827.53. The flaw is reachable over the network and requires no authentication, but does require the victim to visit a crafted HTML page. Successful exploitation allows a remote attacker to execute arbitrary code inside the Chrome sandbox. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-10941 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of publication from upstream feeds, including custom-built images that bundle Chrome or Chromium as a dependency.

Available
Triage

HarborGuard scores this CVE at 8.8 HIGH using the CVSS v3.1 vector, and triage capability includes per-environment compliance policy weighting and automatic routing to the appropriate team inbox within each customer organization.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.53 is available on HarborGuard for any environment found to be running an affected version. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs regression tests, and opens a PR against affected workloads automatically, with a median time from CVE publication to merged patch PR around 90 minutes for high-severity issues.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing the victim to a crafted HTML page, so the Chrome instance must be reachable and able to load remote content.

  • AuthenticationNot required

    No account, session token, or credential of any kind is required to deliver the exploit.

  • Victim interactionRequired

    The victim must navigate to or be redirected to a crafted HTML page, making this a social-engineering or drive-by scenario.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, memory layout luck, or other environmental factors.

Blast Radius

  • A successful attacker executes arbitrary code inside the Chrome renderer sandbox, gaining control of the rendering process for the affected tab.
  • Confidential data visible to the renderer, including page content, session state, and in-memory credentials, is exposed to the attacker.
  • The attacker can tamper with page content and in-memory state within the sandboxed process, potentially staging further exploitation toward a sandbox escape.
  • The compromised renderer process can be crashed or made unavailable, disrupting the user session for the affected tab.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-10941 is active across all connected registries and CI pipelines, matching images that package Chrome or Chromium below 149.0.7827.53. For customers who opt into auto-remediation, HarborGuard rebuilds the affected image at the fixed version (149.0.7827.53), executes the configured regression-test suite, and opens a PR against affected workloads; for high-severity issues, the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy does not permit auto-remediation, the CVE is surfaced in the findings dashboard with fix-version detail so engineering teams can act manually. Customers who cannot upgrade immediately should consider network-policy controls that restrict which origins the containerized Chrome instance can load, reducing exposure to crafted pages while the upgrade is staged.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H