CVE-2026-9879: Out of bounds write in ANGLE in Google Chrome prior to 148
Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
HarborGuard Analysis
HarborGuard analysisSynopsis
An out-of-bounds write vulnerability exists in ANGLE, the graphics translation layer used by Google Chrome versions prior to 148.0.7778.216. The flaw is reachable over the network and requires no authentication, though a victim must visit a crafted HTML page for exploitation to occur. Successful exploitation gives an attacker arbitrary code execution in the context of the browser process. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection of CVE-2026-9879 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all container images in customer registries and CI/CD pipelines, including custom-built images that bundle Chrome or Chromium as a dependency.
AvailableHarborGuard scores this vulnerability at CVSS 8.8 (High) and makes that rating available in every customer environment alongside per-environment compliance policy weighting, routing findings to the appropriate team inbox based on each customer org's configured escalation rules.
AvailableA patched-image rebuild at Chrome 148.0.7778.216 is available on HarborGuard for any environment found running an affected version. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite, and opens a PR against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network by directing the victim to a crafted HTML page hosted on an attacker-controlled server.
- AuthenticationNot required
No account or credential is needed on the target system; any unauthenticated remote attacker can serve the malicious page.
- Victim interactionRequired
The victim must open a crafted HTML page in an affected Chrome browser, making this a social-engineering or drive-by-browsing scenario.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other variable environmental factors.
Blast Radius
- Attacker executes arbitrary code in the browser process, gaining full control over the browser's execution context.
- Attacker reads browser-accessible data including stored session tokens, saved credentials, and page content from any open origin.
- Attacker modifies browser state, injecting content or altering data handled by the renderer and browser process.
- Attacker crashes or destabilizes the browser process, causing a denial of service for the affected user session.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-9879 is active in the scanning pipeline for all customer environments, with results available within minutes of the CVE entering upstream feeds. For environments where Chrome or Chromium is bundled into container images at a version below 148.0.7778.216, a patched rebuild at the fixed version is available. For customers who opt into auto-remediation, HarborGuard performs the rebuild, executes a regression run, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy does not permit auto-remediation, the finding is surfaced in the dashboard with the fix version and affected image list so teams can act manually.
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H