CVE-2026-9877: Use after free in ANGLE in Google Chrome prior to 148
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
HarborGuard Analysis
HarborGuard analysisSynopsis
Use-after-free in the ANGLE graphics layer of Google Chrome prior to version 148.0.7778.216 allows a remote attacker who has already compromised the Chrome renderer process to escape the browser sandbox. The vulnerability is reachable over the network and requires no authentication, though victim interaction and a pre-compromised renderer are both prerequisites. Successful exploitation gives the attacker full code execution outside the sandbox, enabling high-impact compromise of confidentiality, integrity, and availability on the host. A patched-image rebuild at 148.0.7778.216 is available on HarborGuard for affected environments.
HarborGuard Coverage
Detection of CVE-2026-9877 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Google Chrome. Any image carrying a Chrome version below 148.0.7778.216 is flagged automatically in both registry scans and CI/CD pipeline checks.
AvailableHarborGuard scores this CVE at 8.3 HIGH (CVSS v3.1) and weights it further against each customer environment's compliance policy, escalating findings appropriately based on workload exposure. Triage results are routed to the inbox configured for the relevant team within the customer org, with the CVSS vector detail attached for quick review.
AvailableA patched-image rebuild pinned to Chrome 148.0.7778.216 becomes available on HarborGuard the moment the fix version is confirmed against the upstream advisory. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs regression tests against the updated image, and opens a PR against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers a crafted HTML page over the network, so the affected Chrome instance must be reachable or browsing to an attacker-controlled resource.
- AuthenticationNot required
No account or credential is needed; any user browsing to the crafted page is a viable target.
- Victim interactionRequired
The victim must open or be redirected to a crafted HTML page, making a social-engineering or malicious-ad delivery vector necessary.
- Attack complexityDetail
Attack complexity is rated High, meaning the attacker must first achieve a separate renderer-process compromise before this use-after-free can be leveraged for a sandbox escape.
Blast Radius
- Attacker escapes the Chrome sandbox and executes arbitrary code in the context of the browser process on the host.
- With sandbox escape achieved, the attacker reads files and credentials accessible to the user running Chrome, including stored session tokens and local secrets.
- The attacker writes or modifies files on the host filesystem within the user's permissions, enabling persistence mechanisms or data tampering.
- The attacker can crash or destabilize the host-level browser process, causing service disruption for the affected user.
How HarborGuard Handles This
Available on HarborGuard: images containing Google Chrome are matched against CVE-2026-9877 within minutes of the advisory being published, with no manual feed configuration required. A rebuild at the patched version 148.0.7778.216 is available for any environment running an affected image. Where compliance policy permits auto-remediation, HarborGuard performs the rebuild, executes a regression-test run against the new image, and opens a PR against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled. Given the sandbox-escape severity and the High attack complexity requirement (renderer pre-compromise as a prerequisite), teams that cannot immediately rebuild should consider network-policy controls that restrict which internal hosts run Chrome-bundled container workloads, reducing lateral exposure while the patched image is validated.
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H