HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-11198Published Modified CNA Chrome

CVE-2026-11198: Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149

Insufficient validation of untrusted input in Codecs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: Medium)

Metrics

CVSS v3.1
9.6
Severity
CRITICAL
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

Insufficient input validation in the Codecs component of Google Chrome (versions prior to 149.0.7827.53) allows a remote attacker to perform a sandbox escape by convincing a user to open a crafted video file. The vulnerability is reachable over the network with no authentication required, but does require a user to interact with a malicious file. Successful exploitation gives the attacker full confidentiality, integrity, and availability impact beyond the browser sandbox. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle a Chrome or Chromium runtime.

Available
Triage

HarborGuard scores this issue at CVSS 9.6 (Critical) and weights it against each environment's compliance policy before routing alerts to the appropriate team inbox within the customer org.

Available
Patch

A patched-image rebuild pinned to Chrome 149.0.7827.53 is available for any image found to carry an affected version. For customers with auto-remediation enabled, HarborGuard triggers the rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the malicious video file over the network, so the affected Chrome instance must be reachable or the user must browse to attacker-controlled content.

  • AuthenticationNot required

    No account or credential of any privilege level is needed; the attacker requires only that the target visit a page or open a file.

  • Victim interactionRequired

    The exploit is triggered only when a user opens or plays a crafted video file, requiring social engineering to deliver that interaction.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other variable environmental factors.

Blast Radius

  • The attacker escapes the Chrome renderer sandbox, gaining code execution in a context outside the browser's isolation boundary.
  • With sandbox escape achieved, the attacker reads files, stored credentials, and session tokens accessible to the browser process.
  • The attacker can write or modify data on the host, including persisting files or altering application state.
  • The attacker can crash or destabilize the affected service or underlying host process, causing a denial of service.

How HarborGuard Handles This

Available on HarborGuard: any image containing Google Chrome prior to 149.0.7827.53 is flagged at Critical severity within minutes of CVE ingestion. For customers with auto-remediation enabled, HarborGuard rebuilds the image at the fixed version (149.0.7827.53), runs regression tests, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for critical-severity issues is around 90 minutes in environments with auto-remediation active. Where compliance policy requires manual approval, the rebuilt image is staged and the alert is routed to the designated security or platform engineering inbox. Customers who cannot immediately update are advised to apply network-policy controls that restrict access to untrusted media sources and to consider disabling codec-heavy browser features via enterprise policy flags as a compensating control until the patched image is promoted.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H