HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-10988Published Modified CNA Chrome

CVE-2026-10988: Use after free in Views in Google Chrome prior to 149

Use after free in Views in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

Use-after-free in the Views component of Google Chrome (versions prior to 149.0.7827.53) allows a remote attacker who has already compromised the renderer process to escape the browser sandbox via a crafted HTML page. The vulnerability is reachable over the network and requires no authentication, though it does require the victim to visit or interact with a malicious page. Successful exploitation gives the attacker code execution outside the Chrome sandbox, bypassing the main isolation boundary that separates browser processes from the host. A patched-image rebuild at 149.0.7827.53 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection capability is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle or layer Chrome. Any image carrying a Chrome version below 149.0.7827.53 is flagged automatically.

Available
Triage

HarborGuard scores this CVE at CVSS 8.8 (HIGH) and surfaces it accordingly in each customer's triage queue, weighted against that environment's compliance policy. Routing rules direct the finding to the team or inbox configured for HIGH-severity issues in each customer org.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.53 becomes available on HarborGuard for any image found to carry an affected version. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test pass, and opens a pull request against the affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network; the target Chrome instance must be able to reach or load attacker-controlled content.

  • AuthenticationNot required

    No account or credentials are needed; any unauthenticated user browsing the web is a valid target.

  • Victim interactionRequired

    The victim must visit or be directed to a crafted HTML page, making this a social-engineering or malicious-redirect scenario.

  • Attack complexityDetail

    Attack complexity is low; the exploit is reliable and does not depend on race conditions, memory layout, or other unpredictable environmental factors beyond the prerequisite renderer compromise.

Blast Radius

  • Attacker escapes the Chrome sandbox and gains code execution in the context of the browser process on the host operating system.
  • With sandbox escape achieved, the attacker can read files and credentials accessible to the user running Chrome, including stored session tokens and local secrets.
  • The attacker can write to or modify files and persistent storage accessible to that user account.
  • The attacker can crash or destabilize the browser process and any dependent services running under the same user context.

How HarborGuard Handles This

Available on HarborGuard: detection, triage, and rebuild capabilities are ready for this CVE the moment an affected image appears in a customer registry or CI pipeline. For environments with auto-remediation enabled, HarborGuard rebuilds the image at Chrome 149.0.7827.53, runs a regression test pass, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for HIGH-severity issues is around 90 minutes in those environments. Where compliance policy requires manual approval, the finding is routed to the configured team inbox with the CVSS 8.8 score and sandbox-escape context attached. Given the severity of a sandbox escape and the low attack complexity, prioritizing this rebuild ahead of lower-severity findings is advisable for any environment that bundles Chrome in a container image.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H