CVE-2026-10983: Insufficient validation of untrusted input in Dawn in Google Chrome prior to 149
Insufficient validation of untrusted input in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Metrics
- CVSS v3.1
- 9.6
- Severity
- CRITICAL
- Fixed in
- 149.0.7827.53
- Affected Products
- 1
HarborGuard Analysis
Synopsis
Insufficient input validation in Dawn, the WebGPU graphics backend in Google Chrome, allows a remote attacker to escape the browser sandbox via a crafted HTML page. The vulnerability is reachable over the network without any account or credentials, but requires the victim to visit a malicious or attacker-controlled page. Successful exploitation gives the attacker code execution outside the Chrome sandbox, bypassing the primary isolation boundary between web content and the host system. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for affected environments.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Chrome or Chromium. Any image carrying a Chrome version below 149.0.7827.53 is flagged immediately.
AvailableHarborGuard scores this CVE at 9.6 CRITICAL using the published CVSS v3.1 vector, and per-environment compliance policy weighting can escalate or adjust routing based on how each customer org treats browser-component risk. Triage findings are routed to the appropriate team inbox inside each customer organization according to their configured policy.
AvailableA patched-image rebuild at Chrome 149.0.7827.53 becomes available for any affected image once the fix version is confirmed in the upstream feed. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite, and opens a PR against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network by directing the victim to a crafted HTML page, so the Chrome instance must be reachable in a browsing context.
- AuthenticationNot required
No account or credentials of any kind are required; any unauthenticated remote attacker can attempt exploitation.
- Victim interactionRequired
The victim must open or be redirected to a crafted HTML page, making this a social-engineering or drive-by delivery scenario.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and imposes no race conditions or special environmental preconditions on the attacker.
Blast Radius
- The attacker escapes the Chrome sandbox and executes arbitrary code in the context of the host process, breaking the primary isolation boundary.
- With sandbox escape, the attacker reads files, credentials, and session data accessible to the user running Chrome on the host.
- The attacker writes or modifies files on the host filesystem and can persist malicious code across reboots.
- The attacker disrupts or terminates host-level processes, causing denial of service on the affected system.
How HarborGuard Handles This
Available on HarborGuard: detection against this CRITICAL sandbox-escape CVE is active for all scanned images containing Chrome or Chromium below 149.0.7827.53. A patched-image rebuild at the fix version (149.0.7827.53) is available as soon as the upstream fix is confirmed in the ingest pipeline. For customers who opt into auto-remediation, HarborGuard rebuilds the image, runs regression tests, and opens a pull request against affected workloads; for high and critical severity issues, the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, triage findings are routed to the designated inbox with full CVSS context and affected image inventory so the responsible team can act without delay.
Fix available
- Google / Chrome< 149.0.7827.53 (from 149.0.7827.53)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H