CVE-2026-13032: Use after free in WebGL in Google Chrome on Android prior to 149
Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Metrics
- CVSS v3.1
- 9.6
- Severity
- CRITICAL
- Fixed in
- 149.0.7827.197
- Affected Products
- 1
HarborGuard Analysis
Synopsis
Use-after-free in WebGL affects Google Chrome on Android versions prior to 149.0.7827.197. The vulnerability is reachable over the network with no authentication required, but a victim must visit a crafted HTML page. Successful exploitation allows a remote attacker to escape the Chrome sandbox, gaining the ability to read data, tamper with data, and crash or disrupt the affected process with high impact across all three areas. A patched-image rebuild at version 149.0.7827.197 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built Android and Chrome-derived container images. Any image packaging a vulnerable Chrome version below 149.0.7827.197 is flagged automatically.
AvailableHarborGuard scores this CVE at 9.6 CVSS v3.1 Critical and weights findings against each customer organization's compliance policy to determine urgency and routing. Alerts are directed to the appropriate team inbox within each customer org based on configured ownership rules.
AvailableA patched-image rebuild at Chrome 149.0.7827.197 becomes available on HarborGuard for any environment where an affected image is detected. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network; the target Chrome instance must be reachable and the victim must browse to an attacker-controlled or compromised page.
- AuthenticationNot required
No account or credential is needed; any unauthenticated remote attacker can serve the malicious HTML page.
- Victim interactionRequired
The victim must navigate to a crafted HTML page, making this a social-engineering or drive-by scenario requiring at least one user action.
- Attack complexityDetail
Attack complexity is Low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental factors.
Blast Radius
- A successful attacker escapes the Chrome sandbox, breaking the primary isolation boundary between web content and the underlying Android system.
- Confidentiality impact is High: the attacker can read sensitive data accessible to the Chrome process, including stored credentials, session tokens, and browsing history.
- Integrity impact is High: the attacker can write or modify data on the device, including files and application state reachable from the escaped sandbox context.
- Availability impact is High: the attacker can crash or terminate the Chrome process and potentially destabilize dependent system services.
How HarborGuard Handles This
Available on HarborGuard: detection fires within minutes of CVE publication for any customer image packaging a Chrome version below 149.0.7827.197. Given the Critical severity (CVSS 9.6) and the confirmed sandbox-escape primitive, this CVE is surfaced at the highest priority tier. For customers with auto-remediation enabled, HarborGuard initiates a rebuild at the fixed version (149.0.7827.197), runs regression tests against the rebuilt image, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for critical-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuilt image is staged and a review request is routed to the designated owner. Until a rebuild is confirmed deployed, customers can apply network-policy controls to restrict which workloads can load arbitrary external web content, and can enforce browser management policies that block navigation to untrusted origins.
Fix available
- Google / Chrome< 149.0.7827.197 (from 149.0.7827.197)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H