HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-13032Published Modified CNA Chrome

CVE-2026-13032: Use after free in WebGL in Google Chrome on Android prior to 149

Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

Metrics

CVSS v3.1
9.6
Severity
CRITICAL
Fixed in
149.0.7827.197
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

Use-after-free in WebGL affects Google Chrome on Android versions prior to 149.0.7827.197. The vulnerability is reachable over the network with no authentication required, but a victim must visit a crafted HTML page. Successful exploitation allows a remote attacker to escape the Chrome sandbox, gaining the ability to read data, tamper with data, and crash or disrupt the affected process with high impact across all three areas. A patched-image rebuild at version 149.0.7827.197 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built Android and Chrome-derived container images. Any image packaging a vulnerable Chrome version below 149.0.7827.197 is flagged automatically.

Available
Triage

HarborGuard scores this CVE at 9.6 CVSS v3.1 Critical and weights findings against each customer organization's compliance policy to determine urgency and routing. Alerts are directed to the appropriate team inbox within each customer org based on configured ownership rules.

Available
Patch

A patched-image rebuild at Chrome 149.0.7827.197 becomes available on HarborGuard for any environment where an affected image is detected. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network; the target Chrome instance must be reachable and the victim must browse to an attacker-controlled or compromised page.

  • AuthenticationNot required

    No account or credential is needed; any unauthenticated remote attacker can serve the malicious HTML page.

  • Victim interactionRequired

    The victim must navigate to a crafted HTML page, making this a social-engineering or drive-by scenario requiring at least one user action.

  • Attack complexityDetail

    Attack complexity is Low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental factors.

Blast Radius

  • A successful attacker escapes the Chrome sandbox, breaking the primary isolation boundary between web content and the underlying Android system.
  • Confidentiality impact is High: the attacker can read sensitive data accessible to the Chrome process, including stored credentials, session tokens, and browsing history.
  • Integrity impact is High: the attacker can write or modify data on the device, including files and application state reachable from the escaped sandbox context.
  • Availability impact is High: the attacker can crash or terminate the Chrome process and potentially destabilize dependent system services.

How HarborGuard Handles This

Available on HarborGuard: detection fires within minutes of CVE publication for any customer image packaging a Chrome version below 149.0.7827.197. Given the Critical severity (CVSS 9.6) and the confirmed sandbox-escape primitive, this CVE is surfaced at the highest priority tier. For customers with auto-remediation enabled, HarborGuard initiates a rebuild at the fixed version (149.0.7827.197), runs regression tests against the rebuilt image, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for critical-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuilt image is staged and a review request is routed to the designated owner. Until a rebuild is confirmed deployed, customers can apply network-policy controls to restrict which workloads can load arbitrary external web content, and can enforce browser management policies that block navigation to untrusted origins.

See how HarborGuard automates this

Fix available

149.0.7827.197
Affected packages
  • Google / Chrome
    < 149.0.7827.197 (from 149.0.7827.197)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H