HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-11631Published Modified CNA Chrome

CVE-2026-11631: Use after free in Aura in Google Chrome on Windows prior to 149

Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
149.0.7827.103
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

Use-after-free vulnerability in the Aura windowing layer of Google Chrome on Windows, affecting all versions prior to 149.0.7827.103. The vulnerability is reachable over the network but requires the attacker to have already compromised the Chrome renderer process and to trick a user into visiting a crafted HTML page; attack complexity is high due to these prerequisites. Successful exploitation enables a sandbox escape, giving the attacker code execution outside the Chrome sandbox with full confidentiality, integrity, and availability impact on the host. A patched-image rebuild at version 149.0.7827.103 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-11631 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle Chrome or Chromium. No manual configuration is required for detection to apply to newly pushed images.

Available
Triage

HarborGuard surfaces this CVE with its CVSS v3.1 score of 8.3 (HIGH), weighted against each customer environment's compliance policy to determine urgency and routing. Triage findings are delivered to the inbox or ticketing integration configured for the affected workload owner within each customer org.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.103 is available on HarborGuard for any environment where an affected image is detected. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite against the new image, and opens a PR against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by serving a crafted HTML page to the target user's browser.

  • AuthenticationNot required

    No authentication is needed; the attacker only needs to lure the target to a malicious page.

  • Victim interactionRequired

    The target user must visit or be redirected to the attacker-controlled HTML page, making social engineering or malicious-ad delivery a necessary step.

  • Attack complexityDetail

    Exploitation is high complexity: the attacker must first have compromised the Chrome renderer process before this use-after-free can be leveraged for a sandbox escape, introducing a significant staging requirement.

Blast Radius

  • Attacker escapes the Chrome sandbox and executes arbitrary code in the context of the browser process on the Windows host.
  • Reads files, credentials, and session data accessible to the browser process, including stored passwords and cookies.
  • Modifies or deletes files and data writable by the browser process, including browser profile data and downloaded files.
  • Crashes or destabilizes the browser process, causing denial of service for the affected user session.

How HarborGuard Handles This

Available on HarborGuard: images containing Google Chrome prior to 149.0.7827.103 are flagged against this CVE at ingest time, covering both registry scans and pipeline builds. Where compliance policy permits auto-remediation, HarborGuard queues a rebuild of the affected image at version 149.0.7827.103, runs a regression test pass against the rebuilt image, and opens a PR against the affected workload; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled. For environments where auto-remediation is not enabled, the rebuilt image is staged and available for manual promotion. Given the sandbox-escape impact and the renderer-compromise prerequisite, teams that cannot immediately rebuild should consider restricting Chrome-based workloads from accessing untrusted external URLs via network policy until the patched version is deployed.

See how HarborGuard automates this

Fix available

149.0.7827.103
Affected packages
  • Google / Chrome
    < 149.0.7827.103 (from 149.0.7827.103)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H