CVE-2026-11631: Use after free in Aura in Google Chrome on Windows prior to 149
Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 149.0.7827.103
- Affected Products
- 1
HarborGuard Analysis
Synopsis
Use-after-free vulnerability in the Aura windowing layer of Google Chrome on Windows, affecting all versions prior to 149.0.7827.103. The vulnerability is reachable over the network but requires the attacker to have already compromised the Chrome renderer process and to trick a user into visiting a crafted HTML page; attack complexity is high due to these prerequisites. Successful exploitation enables a sandbox escape, giving the attacker code execution outside the Chrome sandbox with full confidentiality, integrity, and availability impact on the host. A patched-image rebuild at version 149.0.7827.103 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection of CVE-2026-11631 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle Chrome or Chromium. No manual configuration is required for detection to apply to newly pushed images.
AvailableHarborGuard surfaces this CVE with its CVSS v3.1 score of 8.3 (HIGH), weighted against each customer environment's compliance policy to determine urgency and routing. Triage findings are delivered to the inbox or ticketing integration configured for the affected workload owner within each customer org.
AvailableA patched-image rebuild at Chrome 149.0.7827.103 is available on HarborGuard for any environment where an affected image is detected. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite against the new image, and opens a PR against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network by serving a crafted HTML page to the target user's browser.
- AuthenticationNot required
No authentication is needed; the attacker only needs to lure the target to a malicious page.
- Victim interactionRequired
The target user must visit or be redirected to the attacker-controlled HTML page, making social engineering or malicious-ad delivery a necessary step.
- Attack complexityDetail
Exploitation is high complexity: the attacker must first have compromised the Chrome renderer process before this use-after-free can be leveraged for a sandbox escape, introducing a significant staging requirement.
Blast Radius
- Attacker escapes the Chrome sandbox and executes arbitrary code in the context of the browser process on the Windows host.
- Reads files, credentials, and session data accessible to the browser process, including stored passwords and cookies.
- Modifies or deletes files and data writable by the browser process, including browser profile data and downloaded files.
- Crashes or destabilizes the browser process, causing denial of service for the affected user session.
How HarborGuard Handles This
Available on HarborGuard: images containing Google Chrome prior to 149.0.7827.103 are flagged against this CVE at ingest time, covering both registry scans and pipeline builds. Where compliance policy permits auto-remediation, HarborGuard queues a rebuild of the affected image at version 149.0.7827.103, runs a regression test pass against the rebuilt image, and opens a PR against the affected workload; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled. For environments where auto-remediation is not enabled, the rebuilt image is staged and available for manual promotion. Given the sandbox-escape impact and the renderer-compromise prerequisite, teams that cannot immediately rebuild should consider restricting Chrome-based workloads from accessing untrusted external URLs via network policy until the patched version is deployed.
Fix available
- Google / Chrome< 149.0.7827.103 (from 149.0.7827.103)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H