CVE-2026-11640: Integer overflow in libyuv in Google Chrome prior to 149
Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 149.0.7827.103
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An integer overflow in libyuv, the YUV image-processing library bundled with Google Chrome, allows a remote attacker who has already compromised the Chrome renderer process to escape the browser sandbox. The attack is delivered over the network by convincing a user to visit a crafted HTML page, and no authentication is required, though exploiting the flaw requires a prior renderer compromise and favorable conditions. Successful exploitation grants the attacker full code execution outside the sandbox, with high impact on confidentiality, integrity, and availability. A patched-image rebuild at Chrome 149.0.7827.103 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection of CVE-2026-11640 is available across every HarborGuard environment; the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Chrome or Chromium as a dependency.
AvailableHarborGuard is capable of scoring this CVE at CVSS 8.3 HIGH and weighting it further against each customer's compliance policy; findings are routable to the appropriate team inbox within each organization based on policy-defined severity thresholds and image ownership.
AvailableA patched-image rebuild at Chrome 149.0.7827.103 is available on HarborGuard for any environment running an affected version. For customers who opt into auto-remediation, HarborGuard can trigger a rebuild, run a regression test suite against the new image, and open a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker must be able to reach the victim's browser over the network, delivering the crafted HTML page via a standard web request.
- AuthenticationNot required
No account credentials or session are needed; any user browsing to the attacker-controlled page is a viable target.
- Victim interactionRequired
The victim must navigate to or be redirected to a crafted HTML page, making social engineering or a malicious ad/link the delivery mechanism.
- Attack complexityDetail
Attack complexity is high; successful exploitation depends on the attacker having already compromised the renderer process and on meeting specific environmental or timing conditions to trigger the integer overflow for a sandbox escape.
Blast Radius
- A successful sandbox escape lets the attacker execute arbitrary code at the privilege level of the Chrome browser process on the host, breaking out of the renderer's security boundary.
- The attacker gains read access to files and data accessible to the browser process, including stored credentials, cookies, and session tokens outside the sandbox.
- The attacker can write to or modify files and system state accessible by the browser process, enabling persistence or lateral movement on the host.
- The Chrome process and dependent services can be crashed or made unavailable, disrupting the user's session and any browser-hosted workloads.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-11640 is active across scanning pipelines and will flag any image that packages a Chrome or Chromium version below 149.0.7827.103. Where compliance policy permits, a rebuilt image at the fixed version is available for deployment. For customers with auto-remediation enabled, HarborGuard can perform the full rebuild, run regression tests against the patched image, and open a pull request against affected workloads; for high-severity issues, median time from CVE publication to a merged patch PR is around 90 minutes in environments with auto-remediation enabled. Customers who have not enabled auto-remediation should prioritize upgrading Chrome to 149.0.7827.103 in any container image that ships a browser binary, and should consider restricting network egress from those containers as a compensating control until the patch is applied.
Fix available
- Google / Chrome< 149.0.7827.103 (from 149.0.7827.103)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H