HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-11152Published Modified CNA Chrome

CVE-2026-11152: Object lifecycle issue in Dawn in Google Chrome prior to 149

Object lifecycle issue in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

Metrics

CVSS v3.1
9.6
Severity
CRITICAL
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free (object lifecycle) vulnerability in Dawn, the WebGPU backend used by Google Chrome, affects all Chrome releases before 149.0.7827.53. The flaw is reachable over the network without authentication, but requires the victim to visit a crafted HTML page. Successful exploitation lets a remote attacker escape Chrome's sandbox, gaining code execution or full access to data and processes outside the browser's isolated environment. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-11152 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle or layer on top of Chrome or Chromium. No manual configuration is needed for the match to fire.

Available
Triage

HarborGuard scores this CVE at 9.6 CVSS v3.1 Critical and is capable of weighting that score against each customer environment's compliance policy to determine urgency. Routing to the correct team inbox within a customer organization is available based on policy configuration.

Available
Patch

A patched-image rebuild pinned to Chrome 149.0.7827.53 is available for any environment HarborGuard identifies as running an affected version. For customers who opt into auto-remediation, HarborGuard can trigger a rebuild, run a regression test suite against the new image, and open a pull request against affected workloads; for Critical-severity issues the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by luring the victim to a crafted HTML page, so the Chrome instance must be reachable or browsing-capable from an internet-connected context.

  • AuthenticationNot required

    No account, session token, or credential of any kind is required; the exploit is delivered entirely through a web page visited by the victim.

  • Victim interactionRequired

    The victim must open or be redirected to a specially crafted HTML page, making this a social-engineering or drive-by-delivery scenario.

  • Attack complexityDetail

    Attack complexity is Low, meaning the exploit is reliable and requires no special race condition, memory layout dependency, or other environmental precondition beyond the victim visiting the page.

Blast Radius

  • The attacker escapes Chrome's sandbox, breaking the primary isolation boundary between web content and the host operating system.
  • With sandbox escape achieved, the attacker reads files, credentials, and session tokens accessible to the user running Chrome.
  • The attacker can write or modify files and data on the host, including persisted application state and configuration.
  • The attacker gains the ability to crash, terminate, or take over processes on the host outside the browser context.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-11152 fires automatically as images are scanned against the updated feed, covering any registry or pipeline image that includes Chrome or a Chromium-based layer below version 149.0.7827.53. For customers who opt into auto-remediation, HarborGuard makes a rebuilt image at the fixed version available, runs regression tests, and opens a pull request against affected workloads. Given the Critical severity (CVSS 9.6) and the sandbox-escape impact, customers are encouraged to prioritize this fix; environments with auto-remediation enabled typically see a merged patch PR within roughly 90 minutes of CVE publication for issues at this severity level. Customers who have not enabled auto-remediation can act on the triage alert manually by pulling the patched rebuild that HarborGuard makes available as soon as the fix version is confirmed in the upstream feed.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H