HarborGuard / CVE
Back to search
HIGHCVE-2026-9884Published Modified CNA Chrome

CVE-2026-9884: Use after free in Browser in Google Chrome on Mac prior to 148

Use after free in Browser in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability affects Google Chrome on macOS in versions prior to 148.0.7778.216. The flaw is reachable over the network without any authentication, though it requires a user to visit a crafted HTML page. Successful exploitation gives a remote attacker arbitrary code execution in the context of the browser process. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Chrome on macOS base layers. Any image carrying a Chrome version below 148.0.7778.216 is flagged automatically in both registry scans and CI/CD pipeline checks.

Available
Triage

HarborGuard scores this finding at CVSS 8.8 (HIGH) and weights it against each environment's compliance policy to determine routing priority. Findings are dispatched to the team inbox configured for the affected workload inside each customer organization, with severity and affected image layers surfaced in the triage detail view.

Available
Patch

A patched-image rebuild at Chrome 148.0.7778.216 becomes available through HarborGuard once the fix version is confirmed in the upstream advisory record. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite against the updated image, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing the victim to an attacker-controlled HTML page, requiring the target Chrome instance to be reachable through normal browser web traffic.

  • AuthenticationNot required

    No account credentials or prior authentication are needed; any unauthenticated remote attacker can serve the malicious page.

  • Victim interactionRequired

    The victim must visit a crafted HTML page, meaning the attacker depends on a social-engineering step such as a phishing link or malicious ad to trigger the bug.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental preconditions.

Blast Radius

  • Attacker executes arbitrary code inside the Chrome browser process on the victim's Mac.
  • Code execution runs under the browser process's privileges, giving access to cookies, saved passwords, and session tokens stored by the browser.
  • Attacker can read and exfiltrate files accessible to the browser process account on the local filesystem.
  • Attacker can disrupt or crash the browser process, terminating all active sessions and tabs.

How HarborGuard Handles This

Available on HarborGuard: detection fires within minutes of CVE publication for any image found to bundle Google Chrome below 148.0.7778.216 on a macOS base layer. For customers with auto-remediation enabled, a rebuild at 148.0.7778.216 is triggered automatically, followed by a regression run and a pull request opened against the affected workload. For high-severity issues, the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the finding is routed to the configured team inbox with full CVSS detail and affected-layer context so reviewers can act without additional investigation. Because this is a browser-level code-execution vulnerability requiring only user navigation, teams that cannot immediately rebuild should consider restricting the deployment contexts in which the affected image is used until the patched version is in place.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H