HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-10971Published Modified CNA Chrome

CVE-2026-10971: Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 149

Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is an insufficient input validation vulnerability in the Printing component of Google Chrome on Windows, affecting versions prior to 149.0.7827.53. A remote attacker who has already compromised the Chrome renderer process can exploit this flaw over the network, without any credentials, by tricking a user into visiting a crafted HTML page. Successful exploitation enables a sandbox escape, giving the attacker the ability to read sensitive data, tamper with files, and disrupt services outside the normally restricted browser sandbox. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection of CVE-2026-10971 is available across every HarborGuard environment, with the CVE matched against customer images, including custom-built images, within minutes of publication from upstream feeds. Any image containing an affected Chrome version on Windows is flagged automatically across customer registries and CI/CD pipelines.

Available
Triage

HarborGuard is capable of scoring this CVE at CVSS 8.3 (HIGH) and weighting it against each customer environment's compliance policy to determine priority. Triage routing to the appropriate team inbox within each customer organization is available as part of the standard pipeline.

Available
Patch

A patched-image rebuild at Chrome version 149.0.7827.53 becomes available on HarborGuard for any environment running an affected version once the fix is confirmed. For customers who opt into auto-remediation, HarborGuard can trigger a rebuild, run regression tests, and open a PR against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing the victim to a crafted HTML page hosted remotely.

  • AuthenticationNot required

    No credentials or account access are needed; the attacker operates as an anonymous remote party.

  • Victim interactionRequired

    The victim must visit a crafted HTML page, meaning the attacker must socially engineer the user into browsing to a malicious URL.

  • Attack complexityDetail

    Exploitation is rated high complexity, meaning the attacker must have already compromised the Chrome renderer process as a prerequisite before this flaw can be leveraged.

Blast Radius

  • Reads sensitive data accessible outside the Chrome sandbox, including stored credentials, session tokens, or files on the Windows host.
  • Modifies files or system state on the Windows host that the sandboxed renderer would normally be prevented from touching.
  • Crashes or destabilizes processes on the host outside the browser sandbox, causing service disruption.
  • Gains full code execution outside the browser sandbox, enabling the attacker to pivot further into the host operating system.

How HarborGuard Handles This

Available on HarborGuard: detection of this CVE is matched against customer images within minutes of publication, covering registries and build pipelines including custom Windows-based Chrome images. For environments running Chrome prior to 149.0.7827.53, a patched-image rebuild at the fix version is available. For customers who opt into auto-remediation, HarborGuard can rebuild the image, execute a regression test run, and open a PR against affected workloads; the median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled. Where compliance policy requires manual review before remediation, the CVE is routed to the designated team inbox with full CVSS context and policy weighting applied.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H