HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-11163Published Modified CNA Chrome

CVE-2026-11163: Use after free in Messages in Google Chrome on Android prior to 149

Use after free in Messages in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)

Metrics

CVSS v3.1
9.6
Severity
CRITICAL
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability exists in the Messages component of Google Chrome on Android in versions prior to 149.0.7827.53. The flaw is reachable over the network without any authentication, but requires the victim to visit a crafted HTML page, making it a social-engineering-assisted attack. Successful exploitation allows a remote attacker to escape the Chrome sandbox and achieve high-impact compromise of confidentiality, integrity, and availability on the affected device. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-11163 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of ingestion from upstream feeds, including custom-built Android-based container images that bundle Chrome. Coverage extends to images in both CI/CD pipelines and production registries.

Available
Triage

HarborGuard scores this CVE at 9.6 CRITICAL based on the CVSS v3.1 vector and weights it against each environment's compliance policy to determine urgency and routing. Triage results are surfaced to the appropriate team inbox within each customer organization automatically.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.53 is available on HarborGuard for any environment found running an affected version. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite against the updated image, and opens a pull request against affected workloads.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing the victim to a crafted HTML page hosted remotely.

  • AuthenticationNot required

    No account or credential is needed on the target service; the attack originates from an unauthenticated remote position.

  • Victim interactionRequired

    The victim must visit or be redirected to a crafted HTML page, requiring a social-engineering step to trigger the use-after-free.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other variable environmental factors.

Blast Radius

  • A successful attacker escapes the Chrome renderer sandbox, breaking the primary isolation boundary between web content and the underlying Android OS.
  • With sandbox escape achieved, the attacker reads sensitive data accessible to the Chrome process, including stored session tokens, saved credentials, and browsing history.
  • The attacker writes or modifies data within the Chrome profile and any storage accessible post-escape, enabling persistent changes or malware installation.
  • The attacker can crash or destabilize the Chrome process and dependent services, causing a denial of service on the affected device.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-11163 is active across all customer scan environments the moment the CVE record is ingested, matching affected Chrome versions against every image in registered pipelines and registries. Given the CRITICAL severity rating (9.6), this CVE is prioritized for immediate triage routing under default compliance policies. For customers who opt into auto-remediation, HarborGuard makes a rebuilt image at Chrome 149.0.7827.53 available, runs regression tests against it, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for critical-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuilt image and triage report are queued for reviewer action without delay.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H