HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-11656Published Modified CNA Chrome

CVE-2026-11656: Use after free in ServiceWorker in Google Chrome prior to 149

Use after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a crafted Chrome Extension. (Chromium security severity: High)

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
149.0.7827.103
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

Use-after-free vulnerability in the ServiceWorker component of Google Chrome prior to version 149.0.7827.103 allows a remote attacker to escape the browser sandbox. The attacker must convince a target user to install a malicious Chrome extension, after which the extension can trigger the freed-memory condition over the network. Successful exploitation gives the attacker high-impact access to confidentiality, integrity, and availability outside the browser sandbox. A patched-image rebuild at 149.0.7827.103 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-11656 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle a Chromium or Chrome binary. Any image carrying a Chrome version below 149.0.7827.103 is flagged automatically.

Available
Triage

Triage is available with the full CVSS v3.1 score of 8.3 (High), weighted against each customer organization's compliance policy to set priority and route findings to the correct team inbox. Per-environment policy weighting means a finding in a production-facing image can be escalated above one in a development-only image without any manual intervention.

Available
Patch

A patched-image rebuild pinned to Chrome 149.0.7827.103 is available on HarborGuard for any image found to carry an affected version. For customers who have auto-remediation enabled, HarborGuard can trigger a rebuild, run a regression test suite against the new image, and open a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the malicious extension payload over the network, so the targeted host must be reachable or the user must browse to an attacker-controlled origin.

  • AuthenticationNot required

    No account or credential is needed; the attacker only needs to get the victim to install the crafted extension.

  • Victim interactionRequired

    The user must be socially engineered into installing a malicious Chrome extension, making victim interaction a hard prerequisite for exploitation.

  • Attack complexityDetail

    The CVSS vector marks complexity as High, meaning the exploit depends on specific memory-state conditions or timing that the attacker cannot fully control, reducing reliability.

Blast Radius

  • The attacker escapes the Chrome renderer sandbox, gaining code execution in a more privileged process context on the host.
  • With sandbox escape achieved, the attacker can read files, credentials, and session tokens accessible to the browser process user account.
  • The attacker can write or modify data on the local filesystem or inject into other running processes at the same privilege level.
  • The attacker can crash or destabilize browser processes and potentially other host-level services, disrupting availability.

How HarborGuard Handles This

Available on HarborGuard: any container image that bundles Chrome below 149.0.7827.103 is detectable as affected, and a rebuild at the patched version is available immediately. For customers who opt into auto-remediation, HarborGuard can rebuild the image, execute the configured regression tests, and open a pull request against affected workloads. For high-severity findings, the median time from CVE publication to a merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy restricts auto-remediation, the finding is routed to the designated team inbox with the CVSS 8.3 High score and fix-version metadata attached, so engineers have everything needed to act without additional research.

See how HarborGuard automates this

Fix available

149.0.7827.103
Affected packages
  • Google / Chrome
    < 149.0.7827.103 (from 149.0.7827.103)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H