CVE-2026-11700: Use after free in Tracing in Google Chrome prior to 149
Use after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 149.0.7827.103
- Affected Products
- 1
HarborGuard Analysis
Synopsis
Use-after-free in the Tracing component of Google Chrome prior to version 149.0.7827.103 allows a remote attacker who has already compromised the renderer process to escape the browser sandbox via a crafted HTML page. The attacker reaches this vulnerability over the network and requires the victim to interact with a malicious page, but no authentication is needed. Successful exploitation gives the attacker full read, write, and execution capability outside the sandbox, effectively compromising the host. A patched-image rebuild at 149.0.7827.103 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI pipelines, including custom-built images that bundle or ship Chrome. Environments scanning images with Chrome versions below 149.0.7827.103 are flagged automatically.
AvailableHarborGuard scores this finding at CVSS 8.3 HIGH and weights it against each environment's compliance policy to determine urgency and routing. Alerts are dispatched to the appropriate team inbox within each customer organization based on configured ownership rules.
AvailableA patched-image rebuild pinned to Chrome 149.0.7827.103 becomes available on HarborGuard once the upstream fix is confirmed. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs the regression test suite against the new image, and opens a PR against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker must reach the victim's browser over the network by serving a crafted HTML page from a remote origin.
- AuthenticationNot required
No account or credential of any kind is required; the exploit is reachable by any unauthenticated visitor to the malicious page.
- Victim interactionRequired
The victim must visit or be redirected to the attacker-controlled page, making social engineering or phishing a prerequisite.
- Attack complexityDetail
Exploitation requires the renderer process to already be compromised before the use-after-free can be used for sandbox escape, introducing an additional prerequisite beyond delivering the crafted page.
Blast Radius
- An attacker who escapes the sandbox gains code execution in the context of the browser process on the host, outside Chrome's security boundary.
- Full confidentiality impact means the attacker reads arbitrary files, stored credentials, cookies, and session tokens accessible to the browser process.
- Full integrity impact means the attacker writes or modifies files and data on the host, including dropping persistent payloads.
- Full availability impact means the attacker can crash or terminate the browser process or other host processes it can reach.
How HarborGuard Handles This
Available on HarborGuard: images containing Chrome below version 149.0.7827.103 are flagged as soon as the CVE enters HarborGuard's feed, which typically occurs within minutes of publication. A rebuild targeting 149.0.7827.103 is available for affected images; for customers with auto-remediation enabled, HarborGuard performs the rebuild, executes a regression run, and opens a PR against impacted workloads. Given the HIGH severity rating and the sandbox-escape impact, this CVE is prioritized in the routing queue. Where compliance policy requires manual approval, the finding is surfaced with full CVSS context and fix-version detail so the owning team can act without additional research. Customers who cannot update immediately should consider restricting network access to environments that serve or run Chrome-based workloads as a compensating control until the patched image is deployed.
Fix available
- Google / Chrome< 149.0.7827.103 (from 149.0.7827.103)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H