HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-11677Published Modified CNA Chrome

CVE-2026-11677: Race in Network in Google Chrome on Mac prior to 149

Race in Network in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker who had compromised the network process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
149.0.7827.103
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A race condition in the network process component of Google Chrome on macOS (versions prior to 149.0.7827.103) allows a remote attacker who has already compromised the network process to escape the browser sandbox. The attack requires the victim to visit a crafted HTML page, is reachable over the network, and does not require any authentication. Successful exploitation gives the attacker full confidentiality, integrity, and availability impact outside the browser sandbox, effectively granting arbitrary code execution in the broader OS context. A patched-image rebuild at version 149.0.7827.103 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection for CVE-2026-11677 is available across every HarborGuard environment; the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle Chrome on macOS base layers.

Available
Triage

HarborGuard scores this CVE at 8.3 HIGH using the CVSS v3.1 vector and can weight that score against each customer environment's compliance policy to determine urgency and route findings to the appropriate team inbox within each customer org.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.103 is available on HarborGuard for any environment found running an affected version. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite, and opens a PR against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the victim over the network by delivering a crafted HTML page, meaning the service or user session must be accessible from a remote network location.

  • AuthenticationNot required

    No account or credentials are needed; the attack is launched against an unauthenticated browsing session.

  • Victim interactionRequired

    The victim must visit a crafted HTML page, requiring a social-engineering step such as a phishing link or malicious ad to trigger the race condition.

  • Attack complexityDetail

    Attack complexity is high, meaning the attacker must win a race condition in the network process, which depends on precise timing and may require multiple attempts or favorable environmental conditions.

Blast Radius

  • The attacker escapes the Chrome browser sandbox on macOS, gaining execution context outside the browser's isolation boundary.
  • With sandbox escape achieved, the attacker reads files, credentials, and session tokens accessible to the user running Chrome.
  • The attacker modifies files or OS-level persistent state, enabling malware installation or privilege escalation beyond the browser.
  • The attacker can crash or disrupt processes running under the same user account, causing service disruption on the affected host.

How HarborGuard Handles This

Available on HarborGuard: detection for this CVE fires within minutes of publication against any customer image that includes Google Chrome on a macOS base layer. Because this is a HIGH severity issue with a confirmed fix at 149.0.7827.103, a patched-image rebuild is available immediately. For customers who opt into auto-remediation, the median time from CVE publication to a merged patch PR for high-severity issues is around 90 minutes, covering the rebuild, regression run, and PR creation against affected workloads. Where compliance policy restricts auto-remediation, findings are surfaced in the customer's configured inbox with fix-version details attached so engineering teams can act manually. HarborGuard continues to monitor the advisory for any revisions to the fix or newly identified affected ranges.

See how HarborGuard automates this

Fix available

149.0.7827.103
Affected packages
  • Google / Chrome
    < 149.0.7827.103 (from 149.0.7827.103)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H