HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-11638Published Modified CNA Chrome

CVE-2026-11638: Use after free in Printing in Google Chrome prior to 149

Use after free in Printing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Metrics

CVSS v3.1
9.6
Severity
CRITICAL
Fixed in
149.0.7827.103
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability in the Printing component of Google Chrome (versions prior to 149.0.7827.103) allows a remote attacker to exploit freed memory by luring a user to a crafted HTML page. The attack requires no authentication and is reachable over the network, but does require the victim to visit or interact with a malicious page. Successful exploitation enables a sandbox escape, giving the attacker full read, write, and availability impact outside Chrome's normal process isolation. A patched-image rebuild at version 149.0.7827.103 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-11638 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that bundle a Chromium or Chrome runtime.

Available
Triage

Triage is available with a CVSS v3.1 score of 9.6 (Critical), weighted against each customer organization's compliance policy to determine urgency and routed to the appropriate team inbox within that organization automatically.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.103 becomes available on HarborGuard as soon as the upstream fix is indexed. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite against the updated image, and opens a PR against affected workloads.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network; the targeted Chrome instance must be reachable or the user must browse to an attacker-controlled page.

  • AuthenticationNot required

    No account or credential is needed; any unauthenticated remote attacker can attempt exploitation.

  • Victim interactionRequired

    The victim must visit or be redirected to a crafted HTML page, making social engineering or a malicious ad the typical delivery mechanism.

  • Attack complexityDetail

    Attack complexity is Low, meaning the exploit is reliable and requires no special race conditions or specific memory layout to succeed.

Blast Radius

  • Attacker escapes the Chrome renderer sandbox and gains code execution in a broader process context.
  • Attacker reads arbitrary data accessible to the browser process, including stored credentials, session tokens, and locally cached files.
  • Attacker modifies files or data writable by the browser process, including browser profile data and locally stored application state.
  • Attacker can crash or destabilize the affected Chrome process, denying service to the user.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-11638 is active across all connected registries and pipelines, matching any image that packages a Chrome or Chromium binary below version 149.0.7827.103. Given the Critical severity (CVSS 9.6) and the confirmed sandbox-escape primitive, this CVE is prioritized at the top tier of HarborGuard's triage routing. For customers with auto-remediation enabled, the flow is: rebuild the image at Chrome 149.0.7827.103, run the configured regression suite, and open a PR against affected workloads. The median time from CVE publication to merged patch PR for Critical-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval before merge, the PR and accompanying scan diff are queued for reviewer action immediately. Customers who cannot update immediately should consider restricting print-dialog access via browser policy, enforcing strict Content Security Policy headers on internal web properties, and isolating workloads that run Chrome in headless or kiosk mode behind additional network controls.

See how HarborGuard automates this

Fix available

149.0.7827.103
Affected packages
  • Google / Chrome
    < 149.0.7827.103 (from 149.0.7827.103)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H