CVE-2026-11144: Use after free in Media in Google Chrome prior to 149
Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: Medium)
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 149.0.7827.53
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A use-after-free vulnerability affects the Media component of Google Chrome prior to version 149.0.7827.53. The flaw is reachable over the network and requires no authentication, but a victim must open a crafted video file, after which an attacker gains arbitrary code execution inside Chrome's renderer sandbox. Successful exploitation gives the attacker full control of the sandboxed renderer process, enabling data theft, content tampering, and potential sandbox-escape chaining. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version of Chrome.
HarborGuard Coverage
Detection of CVE-2026-11144 is available across every HarborGuard environment; the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle a vulnerable Chrome binary. Any image carrying a Chrome version below 149.0.7827.53 is flagged automatically.
AvailableHarborGuard scores this CVE at 8.8 HIGH using the CVSS v3.1 vector and surfaces it with per-environment compliance policy weighting to ensure it reaches the correct team inbox inside each customer organization. Because the score sits at the upper end of HIGH with network exposure and no authentication barrier, default policy thresholds in most environments will treat this as requiring prompt remediation.
AvailableA patched-image rebuild pinned to Chrome 149.0.7827.53 is available on HarborGuard for any environment where a scan identifies an affected image. For customers with auto-remediation enabled, HarborGuard performs the rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads without requiring manual intervention.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the crafted video file over the network, so the victim's browser must be reachable or the attacker must be able to serve content to it via the internet or an internal network.
- AuthenticationNot required
No account or credential is needed; the attacker only needs to get a victim to open a malicious video file.
- Victim interactionRequired
A victim must actively open or be redirected to a crafted video file, making this a social-engineering or drive-by delivery scenario.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental factors.
Blast Radius
- Executes arbitrary code inside Chrome's renderer sandbox, giving the attacker full control of the renderer process.
- Reads in-browser session tokens, saved credentials, and any page content loaded in the affected tab.
- Modifies or injects content into pages the victim is viewing, enabling credential harvesting or malicious redirects.
- Serves as a foothold for sandbox-escape chaining if a second vulnerability targeting the browser process or OS is available.
How HarborGuard Handles This
Available on HarborGuard: any image containing Google Chrome below version 149.0.7827.53 is detectable the moment the CVE enters upstream feeds, typically within minutes of publication. For customers with auto-remediation enabled, HarborGuard rebuilds the affected image at the patched version, runs a regression test run against it, and opens a pull request against the affected workload; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval before patching, the rebuilt image is staged and the PR is queued for reviewer sign-off. In all cases, the finding is routed according to each environment's policy weighting so the right team sees it first without manual triage overhead.
Fix available
- Google / Chrome< 149.0.7827.53 (from 149.0.7827.53)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H