HarborGuard / CVE
Back to search
HIGHCVE-2026-9879Published Modified CNA Chrome

CVE-2026-9879: Out of bounds write in ANGLE in Google Chrome prior to 148

Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

HarborGuard Analysis

HarborGuard analysis

Synopsis

An out-of-bounds write vulnerability exists in ANGLE, the graphics translation layer used by Google Chrome versions prior to 148.0.7778.216. The flaw is reachable over the network and requires no authentication, though a victim must visit a crafted HTML page for exploitation to occur. Successful exploitation gives an attacker arbitrary code execution in the context of the browser process. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-9879 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all container images in customer registries and CI/CD pipelines, including custom-built images that bundle Chrome or Chromium as a dependency.

Available
Triage

HarborGuard scores this vulnerability at CVSS 8.8 (High) and makes that rating available in every customer environment alongside per-environment compliance policy weighting, routing findings to the appropriate team inbox based on each customer org's configured escalation rules.

Available
Patch

A patched-image rebuild at Chrome 148.0.7778.216 is available on HarborGuard for any environment found running an affected version. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite, and opens a PR against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing the victim to a crafted HTML page hosted on an attacker-controlled server.

  • AuthenticationNot required

    No account or credential is needed on the target system; any unauthenticated remote attacker can serve the malicious page.

  • Victim interactionRequired

    The victim must open a crafted HTML page in an affected Chrome browser, making this a social-engineering or drive-by-browsing scenario.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other variable environmental factors.

Blast Radius

  • Attacker executes arbitrary code in the browser process, gaining full control over the browser's execution context.
  • Attacker reads browser-accessible data including stored session tokens, saved credentials, and page content from any open origin.
  • Attacker modifies browser state, injecting content or altering data handled by the renderer and browser process.
  • Attacker crashes or destabilizes the browser process, causing a denial of service for the affected user session.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-9879 is active in the scanning pipeline for all customer environments, with results available within minutes of the CVE entering upstream feeds. For environments where Chrome or Chromium is bundled into container images at a version below 148.0.7778.216, a patched rebuild at the fixed version is available. For customers who opt into auto-remediation, HarborGuard performs the rebuild, executes a regression run, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy does not permit auto-remediation, the finding is surfaced in the dashboard with the fix version and affected image list so teams can act manually.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H