CVE-2026-11113: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Metrics
- CVSS v3.1
- 9.6
- Severity
- CRITICAL
- Fixed in
- 149.0.7827.53
- Affected Products
- 1
HarborGuard Analysis
Synopsis
This is an insufficient input validation vulnerability in ANGLE, the graphics abstraction layer used by Google Chrome prior to version 149.0.7827.53. An attacker who has already compromised the Chrome renderer process can exploit this flaw remotely, without authentication, by luring a victim to a crafted HTML page. Successful exploitation enables a sandbox escape, giving the attacker code execution outside the browser sandbox with the privileges of the browser process. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for affected environments.
HarborGuard Coverage
Detection of CVE-2026-11113 is available across every HarborGuard environment, with the CVE matched against images in customer registries and CI/CD pipelines within minutes of upstream publication. This coverage extends to custom-built images that bundle or ship Chrome as a dependency.
AvailableHarborGuard is capable of scoring this CVE at its published CVSS v3.1 rating of 9.6 (Critical) and weighting that score against each environment's compliance policy to determine urgency. Triage routing to the appropriate team inbox within each customer organization is available automatically based on those policy rules.
AvailableA patched-image rebuild at Chrome 149.0.7827.53 is available on HarborGuard for any environment running an affected version. For customers with auto-remediation enabled, HarborGuard can trigger a rebuild, run regression tests, and open a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker must reach the victim over the network, delivering the crafted HTML page through a browser-accessible URL.
- AuthenticationNot required
No account or credential is needed; any unauthenticated remote attacker can initiate the exploit.
- Victim interactionRequired
The victim must visit or be redirected to a crafted HTML page, making this a social-engineering vector requiring at least one user action.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental factors beyond the pre-condition of renderer compromise.
Blast Radius
- An attacker escapes the Chrome renderer sandbox and executes arbitrary code with the privileges of the browser process on the victim host.
- With browser-level process access, the attacker can read files, credentials, and session data accessible to the browser user account.
- The attacker can write or modify files and persistent data within the browser user's permission scope.
- The attacker can crash or destabilize the browser process, disrupting service for the affected user.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-11113 is active across all connected registries and pipelines, matching any image that ships an affected Chrome build against the published advisory. Given the Critical severity (CVSS 9.6), this CVE is prioritized for fast triage routing. For customers with auto-remediation enabled, HarborGuard can rebuild affected images at Chrome 149.0.7827.53, execute a regression test run, and open a pull request against impacted workloads; median time from CVE publication to merged patch PR for critical-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuilt image and test results are staged and surfaced in the remediation queue for engineer review. Customers who cannot immediately update are advised to consider network-policy controls that restrict untrusted web content delivery to affected Chrome deployments as a compensating control until patching is complete.
Fix available
- Google / Chrome< 149.0.7827.53 (from 149.0.7827.53)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H