CVE-2026-11256: Integer overflow in GPU in Google Chrome prior to 149
Integer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 149.0.7827.53
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An integer overflow in the GPU component of Google Chrome (versions prior to 149.0.7827.53) allows a remote attacker who has already compromised the renderer process to escape the browser sandbox via a crafted HTML page. The attack requires network access, no authentication, but does require the victim to interact with a malicious page, and exploit reliability is reduced by high attack complexity conditions. Successful exploitation gives the attacker code execution outside the Chrome sandbox, with full read, write, and availability impact on the host. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection of CVE-2026-11256 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that bundle a Chromium or Chrome binary.
AvailableHarborGuard scores this CVE at 8.3 HIGH (CVSS v3.1) and is capable of weighting that score against each environment's compliance policy to determine urgency; the resulting finding is routable to the appropriate team inbox within each customer organization.
AvailableA patched-image rebuild at Chrome 149.0.7827.53 is available for any image HarborGuard identifies as running an affected version. For customers who opt into auto-remediation, HarborGuard can perform the rebuild, run a regression test suite, and open a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker must reach the victim over the network by serving a crafted HTML page, as indicated by AV:N in the CVSS vector.
- AuthenticationNot required
No account or credential is needed; the attacker operates as an unauthenticated remote party (PR:N).
- Victim interactionRequired
The victim must visit or load the attacker-controlled HTML page for the exploit chain to trigger (UI:R).
- Attack complexityDetail
Attack complexity is rated High (AC:H), meaning the attacker depends on having already achieved renderer-process compromise before this integer overflow can be used to escape the sandbox.
Blast Radius
- A successful attacker escapes the Chrome sandbox and gains code execution at the privilege level of the browser process on the host.
- With high confidentiality impact (C:H), the attacker reads data accessible to the browser process, including stored credentials, session tokens, and cached content.
- With high integrity impact (I:H), the attacker modifies files, registry entries, or other host-level resources writable by the browser process.
- With high availability impact (A:H), the attacker crashes or otherwise disrupts the browser process and any dependent host services.
How HarborGuard Handles This
Available on HarborGuard: images containing Chrome prior to 149.0.7827.53 are flagged as soon as the CVE is ingested, typically within minutes of publication. For customers who opt into auto-remediation, HarborGuard can rebuild the affected image at the patched version, run regression tests, and open a pull request against affected workloads; for high-severity issues, the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy does not permit auto-remediation, the finding is surfaced in the HarborGuard dashboard with the fix version and affected image list so engineering teams can act manually. Because this exploit requires a pre-compromised renderer process, teams should also consider whether any accompanying renderer-level CVEs are present in the same image and address them together.
Fix available
- Google / Chrome< 149.0.7827.53 (from 149.0.7827.53)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H