CVE-2026-11638: Use after free in Printing in Google Chrome prior to 149
Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Metrics
- CVSS v3.1
- 9.6
- Severity
- CRITICAL
- Fixed in
- 149.0.7827.103
- Affected Products
- 1
HarborGuard Analysis
Synopsis
A use-after-free vulnerability in the Printing component of Google Chrome (versions prior to 149.0.7827.103) allows a remote attacker to exploit freed memory by luring a user to a crafted HTML page. The attack requires no authentication and is reachable over the network, but does require the victim to visit or interact with a malicious page. Successful exploitation enables a sandbox escape, giving the attacker full read, write, and availability impact outside Chrome's normal process isolation. A patched-image rebuild at version 149.0.7827.103 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection of CVE-2026-11638 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that bundle a Chromium or Chrome runtime.
AvailableTriage is available with a CVSS v3.1 score of 9.6 (Critical), weighted against each customer organization's compliance policy to determine urgency and routed to the appropriate team inbox within that organization automatically.
AvailableA patched-image rebuild at Chrome 149.0.7827.103 becomes available on HarborGuard as soon as the upstream fix is indexed. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite against the updated image, and opens a PR against affected workloads.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network; the targeted Chrome instance must be reachable or the user must browse to an attacker-controlled page.
- AuthenticationNot required
No account or credential is needed; any unauthenticated remote attacker can attempt exploitation.
- Victim interactionRequired
The victim must visit or be redirected to a crafted HTML page, making social engineering or a malicious ad the typical delivery mechanism.
- Attack complexityDetail
Attack complexity is Low, meaning the exploit is reliable and requires no special race conditions or specific memory layout to succeed.
Blast Radius
- Attacker escapes the Chrome renderer sandbox and gains code execution in a broader process context.
- Attacker reads arbitrary data accessible to the browser process, including stored credentials, session tokens, and locally cached files.
- Attacker modifies files or data writable by the browser process, including browser profile data and locally stored application state.
- Attacker can crash or destabilize the affected Chrome process, denying service to the user.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-11638 is active across all connected registries and pipelines, matching any image that packages a Chrome or Chromium binary below version 149.0.7827.103. Given the Critical severity (CVSS 9.6) and the confirmed sandbox-escape primitive, this CVE is prioritized at the top tier of HarborGuard's triage routing. For customers with auto-remediation enabled, the flow is: rebuild the image at Chrome 149.0.7827.103, run the configured regression suite, and open a PR against affected workloads. The median time from CVE publication to merged patch PR for Critical-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval before merge, the PR and accompanying scan diff are queued for reviewer action immediately. Customers who cannot update immediately should consider restricting print-dialog access via browser policy, enforcing strict Content Security Policy headers on internal web properties, and isolating workloads that run Chrome in headless or kiosk mode behind additional network controls.
Fix available
- Google / Chrome< 149.0.7827.103 (from 149.0.7827.103)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H