HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-11650Published Modified CNA Chrome

CVE-2026-11650: Use after free in V8 in Google Chrome prior to 149

Use after free in V8 in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
149.0.7827.103
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability in V8, the JavaScript engine embedded in Google Chrome prior to version 149.0.7827.103, allows a remote attacker to execute arbitrary code inside Chrome's sandbox by luring a user to a crafted HTML page. The attack is reachable over the network, requires no authentication, but does require the victim to visit a malicious page. Successful exploitation gives the attacker arbitrary code execution within the browser sandbox, which can serve as a stepping stone to further compromise. A patched-image rebuild at version 149.0.7827.103 is available on HarborGuard for environments running an affected version of Chrome.

HarborGuard Coverage

Detection

Detection of CVE-2026-11650 is available across every HarborGuard environment, with the CVE ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle a Chrome or Chromium binary.

Available
Triage

HarborGuard scores this CVE at 8.8 HIGH per the CVSS v3.1 vector and surfaces findings weighted against each customer organization's compliance policy, routing alerts to the appropriate team inbox based on configured ownership rules.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.103 becomes available on HarborGuard for any image found to include an affected Chrome or Chromium binary. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs the configured regression suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing the victim to a crafted HTML page hosted remotely, so the Chrome instance must be reachable via normal web browsing.

  • AuthenticationNot required

    No account, credential, or prior access to any system is needed; any visitor to the attacker-controlled page is a viable target.

  • Victim interactionRequired

    The victim must navigate to or be redirected to the crafted HTML page, making this a social-engineering vector that requires at least one user action such as clicking a link.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layout, or other unpredictable environmental factors.

Blast Radius

  • The attacker gains arbitrary code execution within Chrome's V8 JavaScript engine sandbox, enabling full control over script execution in that context.
  • Confidential data accessible to the browser process, including session tokens, saved credentials, and page content, is exposed to the attacker.
  • The attacker can read and tamper with data rendered or stored by the browser, including form inputs and locally cached content.
  • The sandboxed process can be used as a launch point for further exploitation attempts targeting the underlying host operating system.

How HarborGuard Handles This

Available on HarborGuard: images containing a Chrome or Chromium binary below version 149.0.7827.103 are flagged automatically once the CVE is ingested, typically within minutes of publication. For customers who opt into auto-remediation, HarborGuard rebuilds the affected image at the patched version, executes the configured regression tests, and opens a pull request against affected workloads; for high-severity issues, the median time from CVE publication to merged patch PR in auto-remediation environments is around 90 minutes. Where compliance policy requires manual approval, the finding is routed to the configured owner inbox with full CVSS context and a pre-staged rebuild ready for review. Customers who cannot immediately update are encouraged to enforce network policies that restrict which internal services can spawn or embed Chrome, reducing the attack surface while the patch is staged for deployment.

See how HarborGuard automates this

Fix available

149.0.7827.103
Affected packages
  • Google / Chrome
    < 149.0.7827.103 (from 149.0.7827.103)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H