HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-11676Published Modified CNA Chrome

CVE-2026-11676: Insufficient validation of untrusted input in Dawn in Google Chrome on Linux and ChromeOS prior to 149

Insufficient validation of untrusted input in Dawn in Google Chrome on Linux and ChromeOS prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
149.0.7827.103
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

Insufficient input validation in Dawn (the WebGPU implementation inside Chrome) affects Google Chrome on Linux and ChromeOS prior to version 149.0.7827.103. The vulnerability is reachable over the network and requires no prior authentication, but the attacker must already have compromised the renderer process and also needs the victim to interact with a crafted HTML page. Successful exploitation allows a full sandbox escape, giving the attacker code execution outside the browser sandbox with high impact on confidentiality, integrity, and availability. A patched-image rebuild at version 149.0.7827.103 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Chrome on Linux or ChromeOS base layers. Any image carrying a Chrome version below 149.0.7827.103 is flagged immediately on scan or push.

Available
Triage

HarborGuard scores this finding at CVSS 8.3 HIGH and weights it against each environment's compliance policy to determine priority and routing. Triage tickets are routed to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.103 becomes available through HarborGuard once the fix version is confirmed in the upstream advisory, as it is here. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the crafted HTML page over the network, so the target host must be reachable through a browser session exposed to remote content.

  • AuthenticationNot required

    No account or credential is needed to serve the malicious page to the victim; the attack is mounted by any remote party.

  • Victim interactionRequired

    The victim must visit or be redirected to a crafted HTML page, making this a social-engineering or drive-by delivery scenario.

  • Attack complexityDetail

    Attack complexity is rated High, meaning the attacker must already have compromised the renderer process before this bug can be used for sandbox escape, introducing a meaningful prerequisite beyond simply serving a page.

Blast Radius

  • A successful attacker escapes the Chrome sandbox entirely, gaining code execution in the context of the host OS user running Chrome.
  • With sandbox escape achieved, the attacker reads files, credentials, and session data accessible to that OS user.
  • The attacker can write or modify files on the host, including configuration files and persistent storage used by other applications.
  • The attacker can crash or disrupt the Chrome process and any host services accessible under the same user context.

How HarborGuard Handles This

Available on HarborGuard: images containing Chrome on Linux or ChromeOS base layers are automatically scanned against this CVE on every push and scheduled rescan. Where compliance policy permits, HarborGuard can trigger a patched-image rebuild pinned to 149.0.7827.103 and, for customers with auto-remediation enabled, will run a regression test pass and open a pull request against affected workloads. For high-severity findings at this CVSS score, the median time from CVE publication to a merged patch PR is around 90 minutes in environments with auto-remediation enabled. Until a rebuild is deployed, network-policy controls that restrict which container workloads can initiate outbound browsing activity, combined with restricting untrusted HTML content sources at the egress layer, serve as compensating controls to reduce exposure surface.

See how HarborGuard automates this

Fix available

149.0.7827.103
Affected packages
  • Google / Chrome
    < 149.0.7827.103 (from 149.0.7827.103)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H