CVE-2026-9873: Use after free in Network in Google Chrome prior to 148
Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
HarborGuard Analysis
HarborGuard analysisSynopsis
Use-after-free in the Network component of Google Chrome (versions before 148.0.7778.216) allows a remote attacker to execute arbitrary code inside the browser sandbox by tricking a user into visiting a crafted HTML page. The vulnerability is reachable over the network and requires no authentication, only a single user interaction (opening the malicious page). Successful exploitation gives the attacker code execution within the Chrome sandbox, with full read, write, and availability impact on the affected process. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection capability is available across every HarborGuard environment: CVE-2026-9873 is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle or vendor Chrome. Images in both registry scans and active CI/CD pipeline checks are covered.
AvailableHarborGuard scores this CVE at 8.8 HIGH (CVSS v3.1) and is capable of applying per-environment compliance policy weighting to adjust severity priority. Triage routing is available to direct findings to the appropriate team inbox within each customer organization based on configured policy.
AvailableA patched-image rebuild at Chrome 148.0.7778.216 is available on HarborGuard for any environment running an affected version. For customers who opt into auto-remediation, HarborGuard is capable of triggering a rebuild, running a regression test suite, and opening a PR against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker must reach the victim over the network, serving a crafted HTML page from a remote origin.
- AuthenticationNot required
No account or credential is needed; any anonymous remote attacker can attempt this exploit.
- Victim interactionRequired
The victim must open or navigate to the attacker-controlled HTML page, making this a social-engineering-dependent attack.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions or specific memory layout prerequisites.
Blast Radius
- Reads confidential data accessible to the Chrome renderer process, including session tokens, page content, and credentials handled in-browser.
- Modifies in-process data and browser state, enabling tampering with rendered content or in-memory credentials.
- Crashes or disrupts the affected Chrome process, causing loss of availability for the browser session.
- Code execution within the Chrome sandbox positions an attacker to chain a sandbox-escape vulnerability for broader host access.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-9873 is active across all connected registries and pipelines, with images matched against the affected version range (Chrome before 148.0.7778.216) as soon as the CVE was published. A patched-image rebuild at 148.0.7778.216 is available for affected environments. Where compliance policy permits auto-remediation, HarborGuard is capable of rebuilding the image, executing a regression run, and opening a PR against affected workloads; for high-severity issues, the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. For environments where auto-remediation is not enabled, the finding appears in the triage queue with CVSS context and fix-version detail so engineers can act manually.
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H