HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-11661Published Modified CNA Chrome

CVE-2026-11661: Use after free in Views in Google Chrome on Windows prior to 149

Use after free in Views in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
149.0.7827.103
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability exists in the Views component of Google Chrome on Windows in versions prior to 149.0.7827.103. The flaw is reachable over the network and requires no authentication, though it does require the attacker to have already compromised the renderer process and to trick a user into visiting a crafted HTML page. Successful exploitation allows the attacker to escape Chrome's sandbox, gaining code execution at the browser process level with access to confidential data, the ability to tamper with the system, and the potential to crash or destabilize the host. A patched-image rebuild at version 149.0.7827.103 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection of CVE-2026-11661 is available across every HarborGuard environment, with the CVE matched against images in customer registries and CI/CD pipelines within minutes of upstream publication. This coverage extends to custom-built images that bundle Chrome or Chromium-derived components on Windows base layers.

Available
Triage

HarborGuard is capable of scoring this CVE at CVSS 8.3 (High) and weighting the result against each environment's compliance policy to determine urgency. Triage routing is available to direct findings to the appropriate team inbox within a customer org based on image ownership and policy thresholds.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.103 is available on HarborGuard for any environment running an affected version. For customers with auto-remediation enabled, HarborGuard can trigger a rebuild, run a regression test suite, and open a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the target over the network by serving a crafted HTML page to a victim's browser.

  • AuthenticationNot required

    No account or credentials are required on the target system to initiate the attack.

  • Victim interactionRequired

    A user must be socially engineered into visiting or loading the attacker's crafted HTML page for exploitation to proceed.

  • Attack complexityDetail

    Exploitation requires the attacker to have already compromised the renderer process, introducing environmental preconditions and making reliable exploitation dependent on chaining this with a separate renderer bug.

Blast Radius

  • A successful attacker escapes Chrome's renderer sandbox and gains execution at the browser process level on the Windows host.
  • Confidential data accessible to the browser process, including stored credentials, session tokens, and browsing history, is exposed to the attacker.
  • The attacker can write or modify files and registry entries accessible to the browser process on the host.
  • The browser process can be crashed or the host destabilized, causing a denial of service for the affected user.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-11661 is active across customer registries and pipelines, matching images that bundle Chrome on Windows against the affected version range below 149.0.7827.103. Where compliance policy permits auto-remediation, HarborGuard can rebuild affected images at the fixed version (149.0.7827.103), execute regression tests, and open a patch PR against impacted workloads; for high-severity issues, median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. For environments where auto-remediation is not enabled, the patched rebuild is flagged and held for manual approval. Because this vulnerability requires a pre-compromised renderer as a precondition, teams may also consider network-policy controls that restrict outbound connections from Chrome-embedding workloads as a compensating control while rollout is completed.

See how HarborGuard automates this

Fix available

149.0.7827.103
Affected packages
  • Google / Chrome
    < 149.0.7827.103 (from 149.0.7827.103)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H