HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-11256Published Modified CNA Chrome

CVE-2026-11256: Integer overflow in GPU in Google Chrome prior to 149

Integer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An integer overflow in the GPU component of Google Chrome (versions prior to 149.0.7827.53) allows a remote attacker who has already compromised the renderer process to escape the browser sandbox via a crafted HTML page. The attack requires network access, no authentication, but does require the victim to interact with a malicious page, and exploit reliability is reduced by high attack complexity conditions. Successful exploitation gives the attacker code execution outside the Chrome sandbox, with full read, write, and availability impact on the host. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-11256 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that bundle a Chromium or Chrome binary.

Available
Triage

HarborGuard scores this CVE at 8.3 HIGH (CVSS v3.1) and is capable of weighting that score against each environment's compliance policy to determine urgency; the resulting finding is routable to the appropriate team inbox within each customer organization.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.53 is available for any image HarborGuard identifies as running an affected version. For customers who opt into auto-remediation, HarborGuard can perform the rebuild, run a regression test suite, and open a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the victim over the network by serving a crafted HTML page, as indicated by AV:N in the CVSS vector.

  • AuthenticationNot required

    No account or credential is needed; the attacker operates as an unauthenticated remote party (PR:N).

  • Victim interactionRequired

    The victim must visit or load the attacker-controlled HTML page for the exploit chain to trigger (UI:R).

  • Attack complexityDetail

    Attack complexity is rated High (AC:H), meaning the attacker depends on having already achieved renderer-process compromise before this integer overflow can be used to escape the sandbox.

Blast Radius

  • A successful attacker escapes the Chrome sandbox and gains code execution at the privilege level of the browser process on the host.
  • With high confidentiality impact (C:H), the attacker reads data accessible to the browser process, including stored credentials, session tokens, and cached content.
  • With high integrity impact (I:H), the attacker modifies files, registry entries, or other host-level resources writable by the browser process.
  • With high availability impact (A:H), the attacker crashes or otherwise disrupts the browser process and any dependent host services.

How HarborGuard Handles This

Available on HarborGuard: images containing Chrome prior to 149.0.7827.53 are flagged as soon as the CVE is ingested, typically within minutes of publication. For customers who opt into auto-remediation, HarborGuard can rebuild the affected image at the patched version, run regression tests, and open a pull request against affected workloads; for high-severity issues, the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy does not permit auto-remediation, the finding is surfaced in the HarborGuard dashboard with the fix version and affected image list so engineering teams can act manually. Because this exploit requires a pre-compromised renderer process, teams should also consider whether any accompanying renderer-level CVEs are present in the same image and address them together.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H