CVE-2026-9890: Use after free in XR in Google Chrome on Windows prior to 148
Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
HarborGuard Analysis
HarborGuard analysisSynopsis
A use-after-free vulnerability affects the XR (extended reality) component of Google Chrome on Windows in versions prior to 148.0.7778.216. The flaw is reachable over the network but requires the attacker to have already compromised the renderer process and to lure a victim into visiting a crafted HTML page. Successful exploitation allows a sandbox escape, giving the attacker the ability to read data, modify files, and disrupt the host process outside Chrome's sandbox boundary. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for affected environments.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle Chrome or Chromium as a dependency.
AvailableHarborGuard scores this CVE at 8.3 HIGH (CVSS v3.1) and can weight that score against each customer environment's compliance policy before routing findings to the appropriate team inbox within that organization.
AvailableA patched-image rebuild pinned to Chrome 148.0.7778.216 becomes available through HarborGuard the moment the fix version is confirmed. For customers with auto-remediation enabled, HarborGuard runs the rebuild, executes a regression test pass, and opens a pull request against every affected workload automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the crafted HTML page over the network, so the targeted service or user must be reachable from an internet or network-adjacent position.
- AuthenticationNot required
No account or credential is needed to serve the malicious page; the attacker only requires prior compromise of the renderer process, not any authentication to the target system.
- Victim interactionRequired
The victim must navigate to or load the attacker-controlled HTML page, making this a social-engineering vector where user action is a prerequisite.
- Attack complexityDetail
Attack complexity is rated High, meaning the attacker must first achieve renderer process compromise before the use-after-free can be leveraged for sandbox escape, introducing significant preconditions beyond just delivering the page.
Blast Radius
- A successful sandbox escape lets the attacker read files and data accessible to the Chrome process on the host Windows system, including session tokens or credentials stored on disk.
- The attacker can write or modify files outside the Chrome sandbox, enabling persistence mechanisms or tampering with locally stored application data.
- The attacker can crash or terminate the Chrome process or interfere with other host processes, causing service disruption for the affected user or workload.
- Because the scope change (S:C) flag is set, impact extends beyond the sandboxed browser context and can affect other components or processes sharing the host.
How HarborGuard Handles This
Available on HarborGuard: scanning for CVE-2026-9890 is active across all connected registries and pipelines, with results weighted by each environment's compliance policy. Where a customer image bundles Chrome or Chromium below 148.0.7778.216, a rebuilt image at the fix version is available. For customers who opt into auto-remediation, HarborGuard triggers the rebuild, runs regression tests, and opens a PR against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Customers not yet on auto-remediation can manually trigger the rebuild from the CVE detail panel or pin the fix version in their base-image configuration.
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H