HarborGuard / CVE
Back to search
HIGHCVE-2026-9873Published Modified CNA Chrome

CVE-2026-9873: Use after free in Network in Google Chrome prior to 148

Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)

HarborGuard Analysis

HarborGuard analysis

Synopsis

Use-after-free in the Network component of Google Chrome (versions before 148.0.7778.216) allows a remote attacker to execute arbitrary code inside the browser sandbox by tricking a user into visiting a crafted HTML page. The vulnerability is reachable over the network and requires no authentication, only a single user interaction (opening the malicious page). Successful exploitation gives the attacker code execution within the Chrome sandbox, with full read, write, and availability impact on the affected process. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection capability is available across every HarborGuard environment: CVE-2026-9873 is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle or vendor Chrome. Images in both registry scans and active CI/CD pipeline checks are covered.

Available
Triage

HarborGuard scores this CVE at 8.8 HIGH (CVSS v3.1) and is capable of applying per-environment compliance policy weighting to adjust severity priority. Triage routing is available to direct findings to the appropriate team inbox within each customer organization based on configured policy.

Available
Patch

A patched-image rebuild at Chrome 148.0.7778.216 is available on HarborGuard for any environment running an affected version. For customers who opt into auto-remediation, HarborGuard is capable of triggering a rebuild, running a regression test suite, and opening a PR against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the victim over the network, serving a crafted HTML page from a remote origin.

  • AuthenticationNot required

    No account or credential is needed; any anonymous remote attacker can attempt this exploit.

  • Victim interactionRequired

    The victim must open or navigate to the attacker-controlled HTML page, making this a social-engineering-dependent attack.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions or specific memory layout prerequisites.

Blast Radius

  • Reads confidential data accessible to the Chrome renderer process, including session tokens, page content, and credentials handled in-browser.
  • Modifies in-process data and browser state, enabling tampering with rendered content or in-memory credentials.
  • Crashes or disrupts the affected Chrome process, causing loss of availability for the browser session.
  • Code execution within the Chrome sandbox positions an attacker to chain a sandbox-escape vulnerability for broader host access.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-9873 is active across all connected registries and pipelines, with images matched against the affected version range (Chrome before 148.0.7778.216) as soon as the CVE was published. A patched-image rebuild at 148.0.7778.216 is available for affected environments. Where compliance policy permits auto-remediation, HarborGuard is capable of rebuilding the image, executing a regression run, and opening a PR against affected workloads; for high-severity issues, the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. For environments where auto-remediation is not enabled, the finding appears in the triage queue with CVSS context and fix-version detail so engineers can act manually.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H