HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-11113Published Modified CNA Chrome

CVE-2026-11113: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

Metrics

CVSS v3.1
9.6
Severity
CRITICAL
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is an insufficient input validation vulnerability in ANGLE, the graphics abstraction layer used by Google Chrome prior to version 149.0.7827.53. An attacker who has already compromised the Chrome renderer process can exploit this flaw remotely, without authentication, by luring a victim to a crafted HTML page. Successful exploitation enables a sandbox escape, giving the attacker code execution outside the browser sandbox with the privileges of the browser process. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection of CVE-2026-11113 is available across every HarborGuard environment, with the CVE matched against images in customer registries and CI/CD pipelines within minutes of upstream publication. This coverage extends to custom-built images that bundle or ship Chrome as a dependency.

Available
Triage

HarborGuard is capable of scoring this CVE at its published CVSS v3.1 rating of 9.6 (Critical) and weighting that score against each environment's compliance policy to determine urgency. Triage routing to the appropriate team inbox within each customer organization is available automatically based on those policy rules.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.53 is available on HarborGuard for any environment running an affected version. For customers with auto-remediation enabled, HarborGuard can trigger a rebuild, run regression tests, and open a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the victim over the network, delivering the crafted HTML page through a browser-accessible URL.

  • AuthenticationNot required

    No account or credential is needed; any unauthenticated remote attacker can initiate the exploit.

  • Victim interactionRequired

    The victim must visit or be redirected to a crafted HTML page, making this a social-engineering vector requiring at least one user action.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental factors beyond the pre-condition of renderer compromise.

Blast Radius

  • An attacker escapes the Chrome renderer sandbox and executes arbitrary code with the privileges of the browser process on the victim host.
  • With browser-level process access, the attacker can read files, credentials, and session data accessible to the browser user account.
  • The attacker can write or modify files and persistent data within the browser user's permission scope.
  • The attacker can crash or destabilize the browser process, disrupting service for the affected user.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-11113 is active across all connected registries and pipelines, matching any image that ships an affected Chrome build against the published advisory. Given the Critical severity (CVSS 9.6), this CVE is prioritized for fast triage routing. For customers with auto-remediation enabled, HarborGuard can rebuild affected images at Chrome 149.0.7827.53, execute a regression test run, and open a pull request against impacted workloads; median time from CVE publication to merged patch PR for critical-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuilt image and test results are staged and surfaced in the remediation queue for engineer review. Customers who cannot immediately update are advised to consider network-policy controls that restrict untrusted web content delivery to affected Chrome deployments as a compensating control until patching is complete.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H