CVE-2026-11697: Insufficient validation of untrusted input in UI in Google Chrome prior to 149
Insufficient validation of untrusted input in UI in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Metrics
- CVSS v3.1
- 9.6
- Severity
- CRITICAL
- Fixed in
- 149.0.7827.103
- Affected Products
- 1
HarborGuard Analysis
Synopsis
Insufficient input validation in the Google Chrome browser UI allows a remote attacker to escape the browser sandbox via a crafted HTML page. The vulnerability is reachable over the network, requires no authentication, and needs only a single user interaction (visiting or being redirected to a malicious page). Successful exploitation grants the attacker full confidentiality, integrity, and availability impact beyond the browser sandbox, enabling code execution, data theft, or service disruption at the host level. A patched-image rebuild at version 149.0.7827.103 is available on HarborGuard for affected environments.
HarborGuard Coverage
Detection capability is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle a Chromium or Chrome binary.
AvailableHarborGuard scores this finding at CVSS 9.6 (Critical) and applies per-environment compliance policy weighting to prioritize it appropriately within each customer org, routing the alert to the team or inbox configured for critical-severity browser vulnerabilities.
AvailableA patched-image rebuild at Chrome 149.0.7827.103 becomes available on HarborGuard for any image found to contain an affected Chrome version. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite, and opens a PR against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network by luring or redirecting the victim to a crafted HTML page hosted on an attacker-controlled server.
- AuthenticationNot required
No account or credentials on any system are needed; any anonymous user can serve the malicious page.
- Victim interactionRequired
The victim must visit or be redirected to the crafted HTML page, making this a social-engineering or drive-by delivery scenario.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and requires no race condition, special memory layout, or other environmental precondition.
Blast Radius
- Attacker escapes the Chrome sandbox and executes arbitrary code in the context of the browser process on the host.
- Reads files, stored credentials, session tokens, and other sensitive data accessible to the browser or the host user account.
- Writes or modifies files and persistent data on the host, including browser profiles, downloaded files, and user directories.
- Crashes or disrupts the browser and any dependent services running under the same user context on the host.
How HarborGuard Handles This
Available on HarborGuard: any image containing Google Chrome prior to 149.0.7827.103 is flagged as affected by this Critical-severity sandbox-escape CVE. For customers who opt into auto-remediation, HarborGuard rebuilds the image at the fixed version (149.0.7827.103), runs the configured regression tests, and opens a PR against affected workloads; median time from CVE publication to merged patch PR for critical-severity issues is around 90 minutes for environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuilt image is staged and the finding is routed to the designated reviewer inbox with full CVSS context attached. Customers who cannot immediately rebuild are advised to apply network-policy controls that restrict which workloads can render arbitrary external HTML content, and to consider feature-flag or configuration gating to disable the affected UI surface until the patched image is deployed.
Fix available
- Google / Chrome< 149.0.7827.103 (from 149.0.7827.103)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H