HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-10961Published Modified CNA Chrome

CVE-2026-10961: Use after free in Chrome for iOS in Google Chrome on iOS prior to 149

Use after free in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability affects Google Chrome for iOS in versions prior to 149.0.7827.53. The flaw is reachable over the network and requires no authentication, though it demands that the attacker has already compromised the renderer process and that the victim interacts with a crafted HTML page. Successful exploitation enables a sandbox escape, giving the attacker the ability to read sensitive data, tamper with content, and crash or disrupt the affected browser process. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI pipelines, including custom-built images that bundle Chrome for iOS dependencies.

Available
Triage

HarborGuard scores this CVE at 8.3 HIGH using the published CVSS v3.1 vector, and is capable of weighting that score against each environment's compliance policy to route the finding to the appropriate team or inbox within the customer organization.

Available
Patch

A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for any environment running an affected version. For customers with auto-remediation enabled, HarborGuard can trigger a rebuild, run a regression test suite against the updated image, and open a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing the victim to a crafted HTML page, so the affected service must be reachable from a remote origin.

  • AuthenticationNot required

    No credentials or account are needed; the attack is initiated by an unauthenticated remote attacker.

  • Victim interactionRequired

    The victim must open or be directed to a crafted HTML page, making this a social-engineering-dependent attack requiring at least one user action.

  • Attack complexityDetail

    Exploitation is rated High complexity because the attacker must have already compromised the renderer process before leveraging this flaw for a sandbox escape, introducing a significant prerequisite condition.

Blast Radius

  • A successful attacker escapes the Chrome renderer sandbox, breaking the primary isolation boundary that separates web content from the underlying OS.
  • With sandbox escape achieved, the attacker reads sensitive data accessible to the browser process, including stored credentials, session tokens, and browsing history.
  • The attacker can modify browser state or inject content into contexts outside the compromised renderer, enabling tampering with data the user views or submits.
  • The attacker can crash or destabilize the browser process, causing a denial of service for the affected user session.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-10961 is active and matches any image in a customer registry or pipeline that bundles a vulnerable version of Chrome for iOS below 149.0.7827.53. For customers with auto-remediation enabled, HarborGuard is capable of rebuilding the image at the fixed version 149.0.7827.53, running a regression test pass against the new image, and opening a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, HarborGuard routes the finding with the full CVSS context and fix-version detail to the designated inbox for human review and sign-off before any change is made.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H