CVE-2026-11050: Use after free in V8 in Google Chrome prior to 149
Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 149.0.7827.53
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A use-after-free vulnerability in V8, the JavaScript engine embedded in Google Chrome prior to version 149.0.7827.53, allows a remote attacker to execute arbitrary code inside the browser sandbox. The vulnerability is reachable over the network and requires no authentication, though the victim must open a crafted HTML page, such as one delivered via a phishing link. Successful exploitation gives an attacker arbitrary code execution within the Chrome sandbox. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI pipelines, including custom-built images that bundle a Chromium or Chrome runtime.
AvailableHarborGuard scores this CVE at 8.8 HIGH using the published CVSS v3.1 vector and weights it further against each customer environment's compliance policy, routing findings to the appropriate team inbox within each customer organization.
AvailableA patched-image rebuild pinned to Chrome 149.0.7827.53 is available on HarborGuard for any environment found running an affected version. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network; the victim's browser must be able to reach the attacker-controlled HTML page.
- AuthenticationNot required
No account or credentials of any kind are needed; any unauthenticated user visiting the page is a valid target.
- Victim interactionRequired
The victim must open a crafted HTML page, for example by clicking a link in a phishing email or being redirected by a malicious advertisement.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other hard-to-control environmental factors.
Blast Radius
- The attacker executes arbitrary code inside the Chrome renderer sandbox, gaining full control over the JavaScript execution context of the affected tab.
- Confidential data processed by the page, including session tokens, form inputs, and any secrets accessible to the page's origin, can be read directly.
- The attacker can modify page content and behavior, enabling credential theft, unauthorized transactions, or injection of further malicious payloads delivered to the user.
- While constrained to the sandbox, code execution in the renderer is commonly chained with a sandbox-escape bug to achieve full host-level compromise.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-11050 is active against all images in connected customer registries and build pipelines, including any custom image that ships a Chrome or Chromium binary. Where compliance policy permits, HarborGuard can trigger a full rebuild at the fixed version (149.0.7827.53), run a regression test pass against the rebuilt image, and open a pull request against affected workloads. For customers who opt into auto-remediation, the median time from CVE publication to a merged patch PR for high-severity issues is around 90 minutes. For environments where auto-remediation is not enabled, the finding appears in the HarborGuard dashboard with the fix version pre-populated so engineers can act without additional research.
Fix available
- Google / Chrome< 149.0.7827.53 (from 149.0.7827.53)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H