HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-10972Published Modified CNA Chrome

CVE-2026-10972: Use after free in Ozone in Google Chrome on Linux prior to 149

Use after free in Ozone in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
9.6
Severity
CRITICAL
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

Use-after-free in the Ozone display platform layer of Google Chrome on Linux allows a remote attacker to escape the Chrome renderer sandbox via a crafted HTML page. The vulnerability is reachable over the network with no authentication required, though the victim must open a malicious page. Successful exploitation gives the attacker code execution outside the browser sandbox, enabling full read, write, and crash-level impact on the host process. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected Chrome version.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds (NVD, OSV, Chrome release advisories) within minutes of publication and matched against all customer images, including custom-built images that bundle a Chrome or Chromium binary. Affected image layers in both registry scans and active CI pipeline builds are flagged automatically.

Available
Triage

HarborGuard scores this CVE at CVSS 9.6 (Critical) and weights it against each environment's compliance policy to determine routing priority. Findings are dispatched to the appropriate team inbox within each customer org, with Critical-severity issues surfaced ahead of lower-severity queue items.

Available
Patch

A patched-image rebuild pinned to Chrome 149.0.7827.53 is available on HarborGuard for any image found to carry an affected version. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite against the new image, and opens a pull request against the affected workload; median time from CVE publication to merged patch PR for Critical-severity issues is around 90 minutes in environments with auto-remediation enabled.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing or luring the victim to a crafted HTML page hosted on an attacker-controlled server.

  • AuthenticationNot required

    No account or credential is required; any unauthenticated user browsing to the malicious page is a viable target.

  • Victim interactionRequired

    The victim must open or be redirected to the attacker's crafted HTML page, making this a social-engineering or malicious-link scenario.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and requires no race condition, specific memory layout, or other environmental precondition.

Blast Radius

  • Attacker escapes the Chrome renderer sandbox and gains code execution in the context of the browser process on the Linux host.
  • With sandbox escape achieved, the attacker reads files, credentials, and session data accessible to the user running Chrome.
  • The attacker writes or modifies files and data within the same user's permissions on the host filesystem.
  • The attacker crashes the browser process or any subprocess it controls, disrupting the user's session and any dependent services.

How HarborGuard Handles This

Available on HarborGuard: any image containing Google Chrome prior to 149.0.7827.53 on Linux is flagged as Critical the moment the CVE record is ingested. Where compliance policy permits, a rebuilt image at the fixed version is queued automatically. For customers who opt into auto-remediation, HarborGuard performs the rebuild, executes regression tests, and opens a pull request against affected workloads, targeting a median end-to-end time of roughly 90 minutes for Critical-severity findings. Customers who manage patching manually receive a prioritized finding with the fixed version pinned in the recommendation detail, ready to act on immediately.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H