HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-11003Published Modified CNA Chrome

CVE-2026-11003: Use after free in WebRTC in Google Chrome prior to 149

Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability in the WebRTC component of Google Chrome prior to version 149.0.7827.53 allows a remote attacker to execute arbitrary code inside the browser sandbox. The bug is reachable over the network without any credentials, but the victim must visit a crafted HTML page. Successful exploitation gives the attacker code execution within the sandboxed renderer process. A patched-image rebuild at 149.0.7827.53 is available on HarborGuard for environments running an affected version of Chrome.

HarborGuard Coverage

Detection

Detection of CVE-2026-11003 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of publication from upstream feeds, including custom-built images that bundle Chrome or Chromium. Any image in a customer registry or CI pipeline containing a vulnerable Chrome version below 149.0.7827.53 is flagged automatically.

Available
Triage

HarborGuard scores this CVE at CVSS 8.8 (HIGH) and weights it against each environment's compliance policy to determine urgency and routing. Triage findings are delivered to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.53 is available on HarborGuard for any environment running an affected version. For customers with auto-remediation enabled, HarborGuard performs the rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing the victim to a crafted HTML page hosted remotely.

  • AuthenticationNot required

    No credentials or account are needed; the attacker requires only that the victim loads the malicious page.

  • Victim interactionRequired

    The victim must actively visit or be redirected to a crafted HTML page, making social engineering or malicious ad delivery the likely delivery vector.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other variable environmental factors.

Blast Radius

  • The attacker executes arbitrary code within the Chrome renderer sandbox process on the victim's machine.
  • High confidentiality impact means the attacker reads data accessible to the renderer, including page content, session tokens, and in-page credentials.
  • High integrity impact means the attacker modifies data within the renderer context, including DOM state and any data the page writes to storage APIs.
  • High availability impact means the attacker crashes or hangs the affected browser process, disrupting the user's session.

How HarborGuard Handles This

Available on HarborGuard: images containing Google Chrome below 149.0.7827.53 are flagged within minutes of the CVE entering upstream feeds, including images built internally from Chromium base layers. For customers with auto-remediation enabled, HarborGuard rebuilds the image at the patched version (149.0.7827.53), runs regression tests, and opens a pull request against affected workloads. For high-severity issues, the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where auto-remediation is not enabled, HarborGuard surfaces the finding with CVSS scoring and routing to the configured team inbox so engineers can action the upgrade manually. As an interim compensating control, network policy rules that restrict which containers can initiate outbound WebRTC or arbitrary HTTP connections reduce the reachable surface until a patched image is deployed.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H