CVE-2026-11642: Use after free in Web Apps in Google Chrome prior to 149
Use after free in Web Apps in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 149.0.7827.103
- Affected Products
- 1
HarborGuard Analysis
Synopsis
Use-after-free in the Web Apps component of Google Chrome (versions prior to 149.0.7827.103) allows a remote attacker who has already compromised the renderer process to escape the browser sandbox by delivering a crafted HTML page. The vulnerability is reachable over the network and requires no authentication, though it does require victim interaction and the attacker must have an established renderer-process foothold. Successful exploitation gives the attacker full read, write, and availability impact beyond the sandbox boundary. A patched-image rebuild at version 149.0.7827.103 is available on HarborGuard for affected environments.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream advisory feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Chrome or Chromium. Any image resolving to a Chrome version below 149.0.7827.103 is flagged immediately.
AvailableHarborGuard scores this issue at 8.3 HIGH (CVSS v3.1) and layers each customer org's compliance-policy weighting on top of that base score to determine urgency. Triage results are routed to the inbox or ticketing integration configured for the affected workload within that org.
AvailableA patched-image rebuild pinned to Chrome 149.0.7827.103 becomes available in HarborGuard as soon as the upstream fix is confirmed. For customers who opt into auto-remediation, HarborGuard runs a rebuild, executes the configured regression suite, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the crafted HTML page over the network, so the target Chrome instance must be reachable and browsing externally accessible content.
- AuthenticationNot required
No account or credential is required; the attack is launched from an unauthenticated remote position.
- Victim interactionRequired
The target user must navigate to or open a crafted HTML page, making social engineering or a malicious link a necessary part of the attack chain.
- Attack complexityDetail
Attack complexity is HIGH, meaning the attacker must already hold a compromised renderer process before this bug can be used to escape the sandbox, introducing a meaningful prerequisite condition.
Blast Radius
- Attacker escapes the Chrome sandbox, gaining code execution in a higher-privilege process context outside browser confinement.
- Confidential data accessible to that process, including stored credentials, session tokens, and files visible to the browser profile, can be read.
- The attacker can write to or modify files and system state reachable by the escaped process.
- The host process can be crashed or rendered unavailable, disrupting the browser and any dependent workflows.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-11642 is active across customer environments, matching any image that ships Chrome below 149.0.7827.103. A patched-image rebuild at 149.0.7827.103 is made available upon confirmation of the upstream release. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs the configured regression tests, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy does not permit auto-remediation, the flagged finding and recommended fix version appear in the dashboard for manual review and promotion. Given the sandbox-escape severity and the renderer-compromise prerequisite, teams unable to update immediately should consider restricting network egress from Chrome-based workloads and disabling untrusted web-app installation features via administrative policy until the patched image is promoted.
Fix available
- Google / Chrome< 149.0.7827.103 (from 149.0.7827.103)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H