CVE-2026-10957: Use after free in Glic in Google Chrome prior to 149
Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 149.0.7827.53
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A use-after-free vulnerability in the Glic component of Google Chrome prior to version 149.0.7827.53 allows a remote attacker to execute arbitrary code inside the browser sandbox by delivering a crafted HTML page. The exploit is reachable over the network and requires no authentication, but does require the victim to visit or interact with a malicious page. Successful exploitation gives the attacker code execution within the Chrome sandbox, which can be a stepping stone to broader compromise. A patched-image rebuild at 149.0.7827.53 is available on HarborGuard for environments running an affected version of Chrome.
HarborGuard Coverage
Detection of CVE-2026-10957 is available across every HarborGuard environment, with the CVE matched against images in customer registries and CI/CD pipelines within minutes of upstream publication. This matching covers custom-built images that bundle Chrome or Chromium, not just official base images.
AvailableTriage is available with CVSS scoring applied at ingestion, surfacing this CVE at 8.8 HIGH so it receives immediate attention in each customer environment. Per-environment compliance policy weighting and team-routing rules then direct the finding to the appropriate inbox inside each customer organization.
AvailableA patched-image rebuild pinned to Chrome 149.0.7827.53 becomes available on HarborGuard as soon as the fix version is confirmed in the upstream advisory. For customers with auto-remediation enabled, HarborGuard can trigger a rebuild, run regression tests against the updated image, and open a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network; the target service (a browser loading the crafted page) must be reachable or the victim must browse to an attacker-controlled URL.
- AuthenticationNot required
No credentials or account access are needed; any anonymous user on the network can serve the malicious HTML page.
- Victim interactionRequired
The victim must visit or be redirected to the crafted HTML page, making this a social-engineering or watering-hole style delivery.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other unpredictable environmental factors.
Blast Radius
- The attacker executes arbitrary code inside the Chrome renderer sandbox, gaining a foothold within the browser process.
- With sandbox escape (a separate step not guaranteed by this CVE alone), the attacker can read files, credentials, and session tokens accessible to the browser user.
- The attacker can modify or exfiltrate browser-stored data including saved passwords, cookies, and cached content.
- The affected browser process can be crashed or held hostage, disrupting the end user's session and any web-based workflows running in that browser.
How HarborGuard Handles This
Available on HarborGuard: images containing Chrome or Chromium below 149.0.7827.53 are flagged against this CVE at ingestion, scored at 8.8 HIGH, and queued for rebuild against the patched version. For customers who opt into auto-remediation, HarborGuard triggers a rebuild at 149.0.7827.53, runs a regression test suite against the resulting image, and opens a pull request against affected workloads. Where compliance policy permits, median time from CVE publication to a merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled. Customers who manage remediation manually receive a prioritized finding with the fix version pinned and a direct link to the upstream Chromium advisory for verification.
Fix available
- Google / Chrome< 149.0.7827.53 (from 149.0.7827.53)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H