HarborGuardharborguardDatabase
Back to search
HIGHCVE-2026-11683Published Modified CNA Chrome

CVE-2026-11683: Use after free in WebCodecs in Google Chrome prior to 149

Use after free in WebCodecs in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
149.0.7827.103
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

A use-after-free vulnerability in the WebCodecs component of Google Chrome prior to version 149.0.7827.103 allows a remote attacker to execute arbitrary code inside the browser sandbox by luring a user to a crafted HTML page. The flaw is reachable over the network and requires no authentication, but does require the victim to visit or interact with a malicious page. Successful exploitation gives the attacker code execution within the Chrome sandbox, which can serve as a stepping stone to further privilege escalation. A patched-image rebuild at version 149.0.7827.103 is available on HarborGuard for environments running an affected version of Chrome.

HarborGuard Coverage

Detection

Detection of CVE-2026-11683 is available across every HarborGuard environment. Vulnerability data is ingested from upstream feeds within minutes of publication and matched against customer images, including custom-built images, in both registry scans and CI/CD pipeline checks.

Available
Triage

HarborGuard scores this CVE at 8.8 HIGH using the recorded CVSS v3.1 vector and weights findings against each customer environment's compliance policy before routing alerts to the appropriate team inbox within that organization.

Available
Patch

A patched-image rebuild pinned to Chrome 149.0.7827.103 becomes available for any image found to carry an affected version. For customers who have opted into auto-remediation, HarborGuard triggers an automated rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network; the target browser must be able to reach and load the attacker-controlled HTML page.

  • AuthenticationNot required

    No account or credential on the target system is needed; any unauthenticated remote attacker can attempt the exploit.

  • Victim interactionRequired

    The victim must visit or be redirected to a crafted HTML page, making this a social-engineering or drive-by-delivery scenario.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other unpredictable environmental factors.

Blast Radius

  • Reads sensitive data accessible within the Chrome renderer process, including page content, stored credentials surfaced by autofill, and in-memory session tokens.
  • Modifies in-process state within the renderer, allowing the attacker to tamper with page content or inject follow-on payloads.
  • Crashes or destabilizes the affected renderer process, causing loss of the current browsing session and any unsaved user data in that context.
  • Establishes a foothold inside the Chrome sandbox that can be chained with a separate sandbox-escape bug to gain broader host-level access.

How HarborGuard Handles This

Available on HarborGuard: any container image carrying Google Chrome earlier than 149.0.7827.103 is flagged against this CVE within minutes of the advisory entering the upstream feed, covering images in connected registries as well as images built and scanned inline in CI/CD pipelines. A rebuild at the patched version is available immediately upon detection. For customers who have opted into auto-remediation, the workflow is fully automated: HarborGuard rebuilds the image at 149.0.7827.103, executes the configured regression test suite, and opens a pull request against each affected workload; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuilt image and a prefilled PR are staged and held for reviewer sign-off. All findings are routed according to each environment's team-routing rules so the right owner sees the alert without manual triage.

See how HarborGuard automates this

Fix available

149.0.7827.103
Affected packages
  • Google / Chrome
    < 149.0.7827.103 (from 149.0.7827.103)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H