HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-10948Published Modified CNA Chrome

CVE-2026-10948: Use after free in WebRTC in Google Chrome prior to 149

Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability in the WebRTC component of Google Chrome prior to version 149.0.7827.53 allows a remote attacker to execute arbitrary code inside the browser sandbox. The attack is reachable over the network and requires no authentication, but does require the victim to visit a crafted HTML page. Successful exploitation gives the attacker arbitrary code execution within the Chrome sandbox. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection capability is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle or ship Chrome as a dependency.

Available
Triage

HarborGuard scores this CVE at CVSS 8.8 (HIGH) and weights it against each environment's compliance policy to determine urgency and routing, directing findings to the appropriate team inbox within each customer organization.

Available
Patch

A patched-image rebuild at Chrome version 149.0.7827.53 becomes available on HarborGuard for any image found to include an affected Chrome version. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite, and opens a PR against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing the victim to a crafted HTML page hosted on an attacker-controlled server.

  • AuthenticationNot required

    No account or credential is needed; any unauthenticated remote attacker can attempt the exploit.

  • Victim interactionRequired

    The victim must visit the crafted HTML page, making this a social-engineering vector requiring the attacker to lure the user.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other unpredictable environmental factors.

Blast Radius

  • Attacker executes arbitrary code inside the Chrome renderer sandbox, enabling further exploitation of the host process.
  • Confidential browser data such as session tokens, stored credentials, and page content becomes readable to the attacker.
  • The attacker can modify in-memory state and injected page content, tampering with data the victim sees or submits.
  • The renderer process can be crashed or made unavailable, disrupting the victim's browser session.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-10948 is active across all customer environments, matching images that bundle Chrome below 149.0.7827.53. A patched rebuild at 149.0.7827.53 is available as soon as an affected image is identified. For customers with auto-remediation enabled, HarborGuard initiates the rebuild, executes regression tests, and opens a patch PR against affected workloads; for high-severity issues, the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. For environments where compliance policy does not permit auto-remediation, the finding is routed to the designated team inbox with full CVSS context and remediation guidance so engineers can act manually.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H