HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-14109Published Modified CNA Chrome

CVE-2026-14109: Insufficient policy enforcement in Mojo in Google Chrome prior to 150

Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

Metrics

CVSS v3.1
9.6
Severity
CRITICAL
Fixed in
150.0.7871.47
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is a sandbox escape vulnerability in the Mojo IPC framework used by Google Chrome versions prior to 150.0.7871.47. It is reachable over the network and requires no authentication, though a victim must visit a crafted HTML page and the attacker must have already compromised the Chrome renderer process. Successful exploitation lets the attacker break out of Chrome's sandbox, gaining full access to the underlying host system including reads, writes, and arbitrary code execution. A patched-image rebuild at version 150.0.7871.47 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle Chrome or Chromium as a dependency.

Available
Triage

HarborGuard scores this CVE at CVSS 9.6 (Critical) and surfaces it with that severity weighting inside each customer org's compliance policy; routing rules direct the finding to the team or inbox configured for critical-severity container issues in each environment.

Available
Patch

A patched-image rebuild pinned to Chrome 150.0.7871.47 is available on HarborGuard for any environment running an affected version. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite against the new image, and opens a PR against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers a crafted HTML page over the network, so the affected Chrome instance must be reachable or browsing to attacker-controlled content.

  • AuthenticationNot required

    No account or credentials are needed; any user who visits the crafted page is a valid target.

  • Victim interactionRequired

    The victim must open a crafted HTML page in Chrome, making this a browser-based social-engineering vector.

  • Attack complexityDetail

    Exploit conditions are described as low-complexity and condition-free once the renderer is compromised, though a renderer compromise is itself a prerequisite chained step.

Blast Radius

  • A successful attacker escapes Chrome's renderer sandbox and gains code execution on the host operating system.
  • Confidential data accessible to the host process, including stored credentials, session tokens, and local files, becomes readable.
  • The attacker can write or modify files on the host, including binaries and configuration, enabling persistence.
  • The host process can be crashed or its resources exhausted, disrupting service for the affected system.

How HarborGuard Handles This

Available on HarborGuard: images containing Chrome or Chromium below 150.0.7871.47 are flagged at Critical severity as soon as the CVE is matched during each ingest cycle. For customers with auto-remediation enabled, HarborGuard rebuilds the image at the fixed version (150.0.7871.47), runs regression tests against the rebuilt image, and opens a PR against affected workloads; median time from CVE publication to merged patch PR for critical-severity issues is around 90 minutes in environments with auto-remediation enabled. For customers who have not opted into auto-remediation, the rebuilt image is staged and the finding is routed to the configured security inbox for manual review and approval. Where compliance policy permits network-level controls in the interim, isolating the container from untrusted external browsing traffic reduces exposure while the patch is applied.

See how HarborGuard automates this

Fix available

150.0.7871.47
Affected packages
  • Google / Chrome
    < 150.0.7871.47 (from 150.0.7871.47)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H