CVE-2026-11003: Use after free in WebRTC in Google Chrome prior to 149
Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 149.0.7827.53
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A use-after-free vulnerability in the WebRTC component of Google Chrome prior to version 149.0.7827.53 allows a remote attacker to execute arbitrary code inside the browser sandbox. The bug is reachable over the network without any credentials, but the victim must visit a crafted HTML page. Successful exploitation gives the attacker code execution within the sandboxed renderer process. A patched-image rebuild at 149.0.7827.53 is available on HarborGuard for environments running an affected version of Chrome.
HarborGuard Coverage
Detection of CVE-2026-11003 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of publication from upstream feeds, including custom-built images that bundle Chrome or Chromium. Any image in a customer registry or CI pipeline containing a vulnerable Chrome version below 149.0.7827.53 is flagged automatically.
AvailableHarborGuard scores this CVE at CVSS 8.8 (HIGH) and weights it against each environment's compliance policy to determine urgency and routing. Triage findings are delivered to the appropriate team inbox within each customer organization based on configured ownership rules.
AvailableA patched-image rebuild at Chrome 149.0.7827.53 is available on HarborGuard for any environment running an affected version. For customers with auto-remediation enabled, HarborGuard performs the rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network by directing the victim to a crafted HTML page hosted remotely.
- AuthenticationNot required
No credentials or account are needed; the attacker requires only that the victim loads the malicious page.
- Victim interactionRequired
The victim must actively visit or be redirected to a crafted HTML page, making social engineering or malicious ad delivery the likely delivery vector.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other variable environmental factors.
Blast Radius
- The attacker executes arbitrary code within the Chrome renderer sandbox process on the victim's machine.
- High confidentiality impact means the attacker reads data accessible to the renderer, including page content, session tokens, and in-page credentials.
- High integrity impact means the attacker modifies data within the renderer context, including DOM state and any data the page writes to storage APIs.
- High availability impact means the attacker crashes or hangs the affected browser process, disrupting the user's session.
How HarborGuard Handles This
Available on HarborGuard: images containing Google Chrome below 149.0.7827.53 are flagged within minutes of the CVE entering upstream feeds, including images built internally from Chromium base layers. For customers with auto-remediation enabled, HarborGuard rebuilds the image at the patched version (149.0.7827.53), runs regression tests, and opens a pull request against affected workloads. For high-severity issues, the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where auto-remediation is not enabled, HarborGuard surfaces the finding with CVSS scoring and routing to the configured team inbox so engineers can action the upgrade manually. As an interim compensating control, network policy rules that restrict which containers can initiate outbound WebRTC or arbitrary HTTP connections reduce the reachable surface until a patched image is deployed.
Fix available
- Google / Chrome< 149.0.7827.53 (from 149.0.7827.53)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H