HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-11640Published Modified CNA Chrome

CVE-2026-11640: Integer overflow in libyuv in Google Chrome prior to 149

Integer overflow in libyuv in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
149.0.7827.103
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An integer overflow in libyuv, the YUV image-processing library bundled with Google Chrome, allows a remote attacker who has already compromised the Chrome renderer process to escape the browser sandbox. The attack is delivered over the network by convincing a user to visit a crafted HTML page, and no authentication is required, though exploiting the flaw requires a prior renderer compromise and favorable conditions. Successful exploitation grants the attacker full code execution outside the sandbox, with high impact on confidentiality, integrity, and availability. A patched-image rebuild at Chrome 149.0.7827.103 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-11640 is available across every HarborGuard environment; the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Chrome or Chromium as a dependency.

Available
Triage

HarborGuard is capable of scoring this CVE at CVSS 8.3 HIGH and weighting it further against each customer's compliance policy; findings are routable to the appropriate team inbox within each organization based on policy-defined severity thresholds and image ownership.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.103 is available on HarborGuard for any environment running an affected version. For customers who opt into auto-remediation, HarborGuard can trigger a rebuild, run a regression test suite against the new image, and open a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must be able to reach the victim's browser over the network, delivering the crafted HTML page via a standard web request.

  • AuthenticationNot required

    No account credentials or session are needed; any user browsing to the attacker-controlled page is a viable target.

  • Victim interactionRequired

    The victim must navigate to or be redirected to a crafted HTML page, making social engineering or a malicious ad/link the delivery mechanism.

  • Attack complexityDetail

    Attack complexity is high; successful exploitation depends on the attacker having already compromised the renderer process and on meeting specific environmental or timing conditions to trigger the integer overflow for a sandbox escape.

Blast Radius

  • A successful sandbox escape lets the attacker execute arbitrary code at the privilege level of the Chrome browser process on the host, breaking out of the renderer's security boundary.
  • The attacker gains read access to files and data accessible to the browser process, including stored credentials, cookies, and session tokens outside the sandbox.
  • The attacker can write to or modify files and system state accessible by the browser process, enabling persistence or lateral movement on the host.
  • The Chrome process and dependent services can be crashed or made unavailable, disrupting the user's session and any browser-hosted workloads.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-11640 is active across scanning pipelines and will flag any image that packages a Chrome or Chromium version below 149.0.7827.103. Where compliance policy permits, a rebuilt image at the fixed version is available for deployment. For customers with auto-remediation enabled, HarborGuard can perform the full rebuild, run regression tests against the patched image, and open a pull request against affected workloads; for high-severity issues, median time from CVE publication to a merged patch PR is around 90 minutes in environments with auto-remediation enabled. Customers who have not enabled auto-remediation should prioritize upgrading Chrome to 149.0.7827.103 in any container image that ships a browser binary, and should consider restricting network egress from those containers as a compensating control until the patch is applied.

See how HarborGuard automates this

Fix available

149.0.7827.103
Affected packages
  • Google / Chrome
    < 149.0.7827.103 (from 149.0.7827.103)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H