CVE-2026-11085: Integer overflow in GPU in Google Chrome on Android prior to 149
Integer overflow in GPU in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 149.0.7827.53
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An integer overflow in the GPU component of Google Chrome on Android (versions before 149.0.7827.53) allows a remote attacker to trigger out-of-bounds memory access by luring a user to a crafted HTML page. The attack is reachable over the network and requires no authentication, but does require the victim to visit a malicious page. Successful exploitation gives an attacker read and write access to process memory and can crash the browser. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for affected environments.
HarborGuard Coverage
Detection of CVE-2026-11085 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of ingestion from upstream feeds, including custom-built images that bundle a Chrome runtime. Coverage extends to both registry scans and in-pipeline image checks at build time.
AvailableHarborGuard scores this CVE at CVSS 8.8 (HIGH) and weights it against each environment's compliance policy to determine routing priority. Triage notifications are delivered to the inbox or ticket queue configured for the affected workload's owner inside each customer org.
AvailableA patched-image rebuild at Chrome 149.0.7827.53 is available on HarborGuard for any image found to include an affected version of Chrome on Android. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite against the new image, and opens a PR against the affected workload automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network by directing the victim to a crafted HTML page served from any internet-accessible host.
- AuthenticationNot required
No account or credentials are needed; any unauthenticated visitor to the attacker-controlled page is a viable target.
- Victim interactionRequired
The victim must open a crafted HTML page, meaning the attacker must socially engineer a click, redirect, or ad delivery to reach the vulnerable code path.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layout, or other hard-to-control environmental factors.
Blast Radius
- A successful attacker reads arbitrary memory from the Chrome GPU process, which may include cached page content, authentication tokens, or other sensitive in-memory data.
- The attacker writes to out-of-bounds memory regions, enabling modification of internal browser state or escalation toward code execution within the renderer or GPU process.
- The overflow can corrupt process memory in ways that crash the Chrome browser, causing a denial of service for the affected user session.
- On Android, a compromised GPU process may serve as a stepping stone for further sandbox escape attempts targeting the underlying OS.
How HarborGuard Handles This
Available on HarborGuard: any image in a customer registry or build pipeline that bundles Google Chrome for Android at a version below 149.0.7827.53 is flagged automatically within minutes of CVE publication. For customers who opt into auto-remediation, HarborGuard rebuilds the image at the fixed version (149.0.7827.53), runs regression tests, and opens a PR against affected workloads; for HIGH-severity issues the median time from CVE publication to a merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual review, the CVE appears in the triage queue with full CVSS context and fix-version detail so an engineer can approve the rebuild on their own schedule.
Fix available
- Google / Chrome< 149.0.7827.53 (from 149.0.7827.53)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H