HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-11116Published Modified CNA Chrome

CVE-2026-11116: Use after free in Chromoting in Google Chrome prior to 149

Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Medium)

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability in the Chromoting component of Google Chrome (versions prior to 149.0.7827.53) allows a remote attacker to execute arbitrary code by sending malicious network traffic. The vulnerability is reachable over the network, requires no authentication, but does require the victim to interact with crafted content. Successful exploitation gives the attacker full code execution in the context of the browser process, enabling data theft, tampering, and service disruption. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection of CVE-2026-11116 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle or depend on Chrome. Any image in a customer registry or CI pipeline carrying a vulnerable Chrome version will surface a finding automatically.

Available
Triage

HarborGuard scores this finding at CVSS 8.8 (HIGH) and weights it against each environment's compliance policy to determine severity routing. Findings are directed to the appropriate team inbox within each customer organization based on image ownership and policy configuration.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.53 is available on HarborGuard for any environment running an affected version. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite, and opens a PR against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the victim's browser over the network by delivering malicious network traffic to the Chromoting component.

  • AuthenticationNot required

    No account or credentials are needed; the attacker requires no prior authentication to trigger the vulnerability.

  • Victim interactionRequired

    The victim must interact with attacker-controlled content (for example, visiting a malicious page or opening crafted remote-desktop session data) to trigger the use-after-free.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions or specific memory-layout preconditions.

Blast Radius

  • A successful attacker executes arbitrary code in the context of the Chrome browser process on the victim's machine.
  • The attacker reads browser-stored data including session tokens, saved passwords, and cookies for sites the victim is authenticated to.
  • The attacker modifies local browser state, injecting content or altering stored credentials and browsing data.
  • The attacker can crash or destabilize the browser process, causing denial of service for the affected user session.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-11116 is active across all scanning environments, matching images against the vulnerable Chrome version range the moment the advisory was ingested. Where compliance policy permits auto-remediation, HarborGuard rebuilds affected images at Chrome 149.0.7827.53, runs a regression test suite against the rebuilt image, and opens a PR targeting affected workloads. For HIGH-severity issues, the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. For environments where auto-remediation is not enabled, the finding is routed to the configured team inbox with CVSS scoring and policy-weighted severity attached, so engineers can assess and act on it directly. If an immediate rebuild is not feasible, consider network-policy controls that restrict Chromoting traffic to trusted sources as a compensating measure until the patched image is deployed.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H