CVE-2026-11293: Use after free in Input in Google Chrome prior to 149
Use after free in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
Metrics
- CVSS v3.1
- 9.6
- Severity
- CRITICAL
- Fixed in
- 149.0.7827.53
- Affected Products
- 1
HarborGuard Analysis
Synopsis
Use-after-free in the Input component of Google Chrome (all versions prior to 149.0.7827.53) allows a remote attacker to exploit freed memory by delivering a crafted HTML page to a victim's browser. The vulnerability is reachable over the network, requires no authentication, and succeeds once a user visits or is redirected to a malicious page. Successful exploitation enables a sandbox escape, giving the attacker full read, write, and execution capabilities beyond the browser sandbox. A patched-image rebuild at version 149.0.7827.53 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection of CVE-2026-11293 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against container images in customer registries and CI/CD pipelines, including custom-built images that bundle a Chromium or Chrome binary.
AvailableHarborGuard scores this CVE at CVSS 9.6 Critical and is capable of weighting that score against each environment's compliance policy to surface priority routing; triage tickets can be directed to the appropriate team inbox within each customer organization based on configured ownership rules.
AvailableA patched-image rebuild at Chrome 149.0.7827.53 becomes available on HarborGuard for any image found to carry an affected version. For customers with auto-remediation enabled, HarborGuard performs the rebuild, runs a regression test suite, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for critical-severity issues is around 90 minutes in environments with auto-remediation enabled.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network; the victim's browser must be able to reach or be directed to the attacker-controlled page.
- AuthenticationNot required
No account or credential of any kind is needed; any user who visits the crafted page is exposed.
- Victim interactionRequired
The victim must open or be redirected to a crafted HTML page, making this a social-engineering or malicious-link delivery scenario.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and requires no race conditions, special memory layout, or other environmental preconditions.
Blast Radius
- A successful attacker escapes the Chrome renderer sandbox, gaining code execution in the context of the browser process on the victim host.
- With sandbox escape achieved, the attacker can read files, stored credentials, and session tokens accessible to the browser process.
- The attacker can write or modify files and data reachable by the browser process, including user profile data and cached content.
- The browser process can be crashed or held, disrupting the user session and any dependent services relying on the browser runtime.
How HarborGuard Handles This
Available on HarborGuard: any container image that bundles Google Chrome below version 149.0.7827.53 is flagged as carrying a Critical (CVSS 9.6) use-after-free with sandbox-escape impact. Where a customer's registry or pipeline contains such an image, HarborGuard is capable of matching it against this CVE within minutes of the advisory being ingested. For customers who opt into auto-remediation, HarborGuard rebuilds the image at the patched version (149.0.7827.53), executes a regression run, and opens a pull request against affected workloads; for critical-severity issues, median time from publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. For environments where compliance policy does not permit automatic remediation, HarborGuard surfaces the finding with full CVSS detail and triage routing so engineering teams can act manually. Given the over-the-network delivery vector and no-authentication requirement, prioritizing this patch quickly is strongly advisable for any image that ships Chrome to end users.
Fix available
- Google / Chrome< 149.0.7827.53 (from 149.0.7827.53)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H