HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-11144Published Modified CNA Chrome

CVE-2026-11144: Use after free in Media in Google Chrome prior to 149

Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: Medium)

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability affects the Media component of Google Chrome prior to version 149.0.7827.53. The flaw is reachable over the network and requires no authentication, but a victim must open a crafted video file, after which an attacker gains arbitrary code execution inside Chrome's renderer sandbox. Successful exploitation gives the attacker full control of the sandboxed renderer process, enabling data theft, content tampering, and potential sandbox-escape chaining. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version of Chrome.

HarborGuard Coverage

Detection

Detection of CVE-2026-11144 is available across every HarborGuard environment; the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle a vulnerable Chrome binary. Any image carrying a Chrome version below 149.0.7827.53 is flagged automatically.

Available
Triage

HarborGuard scores this CVE at 8.8 HIGH using the CVSS v3.1 vector and surfaces it with per-environment compliance policy weighting to ensure it reaches the correct team inbox inside each customer organization. Because the score sits at the upper end of HIGH with network exposure and no authentication barrier, default policy thresholds in most environments will treat this as requiring prompt remediation.

Available
Patch

A patched-image rebuild pinned to Chrome 149.0.7827.53 is available on HarborGuard for any environment where a scan identifies an affected image. For customers with auto-remediation enabled, HarborGuard performs the rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads without requiring manual intervention.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the crafted video file over the network, so the victim's browser must be reachable or the attacker must be able to serve content to it via the internet or an internal network.

  • AuthenticationNot required

    No account or credential is needed; the attacker only needs to get a victim to open a malicious video file.

  • Victim interactionRequired

    A victim must actively open or be redirected to a crafted video file, making this a social-engineering or drive-by delivery scenario.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental factors.

Blast Radius

  • Executes arbitrary code inside Chrome's renderer sandbox, giving the attacker full control of the renderer process.
  • Reads in-browser session tokens, saved credentials, and any page content loaded in the affected tab.
  • Modifies or injects content into pages the victim is viewing, enabling credential harvesting or malicious redirects.
  • Serves as a foothold for sandbox-escape chaining if a second vulnerability targeting the browser process or OS is available.

How HarborGuard Handles This

Available on HarborGuard: any image containing Google Chrome below version 149.0.7827.53 is detectable the moment the CVE enters upstream feeds, typically within minutes of publication. For customers with auto-remediation enabled, HarborGuard rebuilds the affected image at the patched version, runs a regression test run against it, and opens a pull request against the affected workload; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval before patching, the rebuilt image is staged and the PR is queued for reviewer sign-off. In all cases, the finding is routed according to each environment's policy weighting so the right team sees it first without manual triage overhead.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H