HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-11050Published Modified CNA Chrome

CVE-2026-11050: Use after free in V8 in Google Chrome prior to 149

Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability in V8, the JavaScript engine embedded in Google Chrome prior to version 149.0.7827.53, allows a remote attacker to execute arbitrary code inside the browser sandbox. The vulnerability is reachable over the network and requires no authentication, though the victim must open a crafted HTML page, such as one delivered via a phishing link. Successful exploitation gives an attacker arbitrary code execution within the Chrome sandbox. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI pipelines, including custom-built images that bundle a Chromium or Chrome runtime.

Available
Triage

HarborGuard scores this CVE at 8.8 HIGH using the published CVSS v3.1 vector and weights it further against each customer environment's compliance policy, routing findings to the appropriate team inbox within each customer organization.

Available
Patch

A patched-image rebuild pinned to Chrome 149.0.7827.53 is available on HarborGuard for any environment found running an affected version. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network; the victim's browser must be able to reach the attacker-controlled HTML page.

  • AuthenticationNot required

    No account or credentials of any kind are needed; any unauthenticated user visiting the page is a valid target.

  • Victim interactionRequired

    The victim must open a crafted HTML page, for example by clicking a link in a phishing email or being redirected by a malicious advertisement.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other hard-to-control environmental factors.

Blast Radius

  • The attacker executes arbitrary code inside the Chrome renderer sandbox, gaining full control over the JavaScript execution context of the affected tab.
  • Confidential data processed by the page, including session tokens, form inputs, and any secrets accessible to the page's origin, can be read directly.
  • The attacker can modify page content and behavior, enabling credential theft, unauthorized transactions, or injection of further malicious payloads delivered to the user.
  • While constrained to the sandbox, code execution in the renderer is commonly chained with a sandbox-escape bug to achieve full host-level compromise.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-11050 is active against all images in connected customer registries and build pipelines, including any custom image that ships a Chrome or Chromium binary. Where compliance policy permits, HarborGuard can trigger a full rebuild at the fixed version (149.0.7827.53), run a regression test pass against the rebuilt image, and open a pull request against affected workloads. For customers who opt into auto-remediation, the median time from CVE publication to a merged patch PR for high-severity issues is around 90 minutes. For environments where auto-remediation is not enabled, the finding appears in the HarborGuard dashboard with the fix version pre-populated so engineers can act without additional research.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H