CVE-2026-10960: Uninitialized Use in Codecs in Google Chrome prior to 149
Uninitialized Use in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 149.0.7827.53
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An uninitialized memory use vulnerability in Google Chrome's codec handling allows a remote attacker who has already compromised the renderer process to escape Chrome's sandbox via a crafted HTML page. The attack requires no authentication but does need the victim to visit a malicious page, and it is reachable over the network with high attack complexity. Successful exploitation gives the attacker full read, write, and crash capability outside the sandbox, effectively turning a renderer compromise into a host-level foothold. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle a Chrome or Chromium runtime.
AvailableHarborGuard scores this finding at CVSS 8.3 (High) and weights it against each environment's compliance policy before routing the alert to the appropriate team inbox inside the customer org.
AvailableA patched-image rebuild at Chrome 149.0.7827.53 becomes available on HarborGuard for any image found to carry an affected version. For customers with auto-remediation enabled, HarborGuard triggers the rebuild, runs a regression test suite, and opens a PR against the affected workload automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the crafted HTML page over the network, so the target service or browser must be reachable from an external or remote origin.
- AuthenticationNot required
No account or credential is needed; any unauthenticated user who visits the malicious page is a viable target.
- Victim interactionRequired
The victim must navigate to or be redirected to a crafted HTML page, making social engineering or a malicious ad/link a prerequisite.
- Attack complexityDetail
Attack complexity is High, meaning the attacker must first achieve renderer-process compromise before this sandbox-escape primitive becomes usable, introducing a multi-stage dependency.
Blast Radius
- The attacker reads arbitrary memory outside the Chrome sandbox, including stored credentials, session tokens, and data from other browser processes.
- The attacker writes to memory outside the sandbox, enabling code injection or persistent modification of host-level data.
- The attacker can crash the host-side Chrome process or dependent services, causing denial of service beyond the sandboxed renderer.
- Combined read-write access outside the sandbox effectively grants a host-level foothold, allowing further lateral movement within the container or underlying node.
How HarborGuard Handles This
Available on HarborGuard: images carrying any Chrome version below 149.0.7827.53 are flagged as soon as the CVE is ingested, typically within minutes of publication. For customers with auto-remediation enabled, HarborGuard rebuilds the image at the fixed version, runs a regression test suite, and opens a PR against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in auto-remediation environments. Where compliance policy requires manual approval, the rebuilt image at 149.0.7827.53 is staged and the alert is routed to the responsible team for review. Given the sandbox-escape nature of this CVE, customers who cannot immediately update are advised to apply network-policy isolation to workloads running Chrome-based runtimes and to restrict egress to reduce the attacker's ability to exploit a compromised renderer.
Fix available
- Google / Chrome< 149.0.7827.53 (from 149.0.7827.53)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H