HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-11282Published Modified CNA Chrome

CVE-2026-11282: Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149

Insufficient policy enforcement in Sandbox in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

Metrics

CVSS v3.1
9.6
Severity
CRITICAL
Fixed in
149.0.7827.53
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is an insufficient policy enforcement flaw in the sandbox component of Google Chrome on Linux, affecting all versions prior to 149.0.7827.53. The vulnerability is reachable over the network and requires no authentication, but does require the victim to visit a crafted HTML page. Successful exploitation gives a remote attacker the ability to escape Chrome's sandbox, enabling full read, write, and availability impact on the underlying host. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Chrome on Linux. Any image carrying a Chrome version below 149.0.7827.53 on a Linux base is flagged automatically.

Available
Triage

HarborGuard scores this CVE at CVSS 9.6 (Critical) and is capable of weighting that score against each environment's compliance policy to determine urgency and escalation path. Triage routing routes findings to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.53 is available for any environment running an affected version. For customers who opt into auto-remediation, HarborGuard is capable of triggering a rebuild, running a regression test suite, and opening a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing the victim to a remote crafted HTML page, so the Chrome instance must be reachable via normal browser traffic.

  • AuthenticationNot required

    No account credentials or prior authentication of any kind are needed to deliver the malicious page to the victim.

  • Victim interactionRequired

    The victim must open or be redirected to a crafted HTML page, making this a social-engineering or malicious-link scenario.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental factors.

Blast Radius

  • A successful sandbox escape lets the attacker execute arbitrary code outside the Chrome sandbox process, with the privileges of the browser's OS-level user account.
  • Confidential data accessible to that user account, including files, session tokens, and credentials stored on disk, becomes readable.
  • The attacker can write or modify files and persistent data within reach of the compromised user account.
  • The attacker can crash or disrupt the browser process and any dependent services running under the same user context.

How HarborGuard Handles This

Available on HarborGuard: detection for this Critical-severity sandbox escape is active the moment the CVE record is ingested, matching any Linux-based image bundling Chrome below 149.0.7827.53. Where compliance policy permits, a patched rebuild at 149.0.7827.53 becomes available immediately; for customers who opt into auto-remediation, HarborGuard is capable of performing the rebuild, executing regression tests, and opening a pull request against affected workloads, with a median time from CVE publication to merged patch PR of around 90 minutes for high and critical-severity issues in environments with auto-remediation enabled. Customers who manage remediation manually can use the HarborGuard finding to prioritize upgrading the Chrome package in affected base images or pipeline stages without delay.

See how HarborGuard automates this

Fix available

149.0.7827.53
Affected packages
  • Google / Chrome
    < 149.0.7827.53 (from 149.0.7827.53)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H