HarborGuard / CVE
Back to search
HIGHCVE-2026-9893Published Modified CNA Chrome

CVE-2026-9893: Use after free in Skia in Google Chrome prior to 148

Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)

HarborGuard Analysis

HarborGuard analysis

Synopsis

Use-after-free in the Skia graphics library within Google Chrome (versions prior to 148.0.7778.216) is reachable over the network and requires no authentication, but does require the attacker to have already compromised the renderer process and to trick a user into visiting a crafted HTML page. Successful exploitation allows the attacker to escape Chrome's sandbox, gaining the ability to read, modify, or crash processes outside the browser's containment boundary. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection capability is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle a Chrome or Chromium binary.

Available
Triage

HarborGuard scores this CVE at 8.3 HIGH (CVSS v3.1) and can weight that score against each customer environment's compliance policy, routing findings to the appropriate team inbox within each organization.

Available
Patch

A patched-image rebuild at Chrome 148.0.7778.216 is available on HarborGuard for any image found to carry an affected version. For customers with auto-remediation enabled, HarborGuard performs the rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing the victim to a crafted HTML page hosted on an attacker-controlled server.

  • AuthenticationNot required

    No account or credential is needed; the attack is launched from an unauthenticated network position.

  • Victim interactionRequired

    The victim must visit or be redirected to a crafted HTML page, making social engineering or a malicious link a necessary part of the attack chain.

  • Attack complexityDetail

    Exploitation is rated high complexity because the attacker must first compromise the Chrome renderer process before the use-after-free can be leveraged for a sandbox escape.

Blast Radius

  • The attacker escapes Chrome's renderer sandbox, breaking out of the containment boundary intended to limit browser-process damage.
  • With sandbox escape achieved, the attacker reads files, credentials, and session data accessible to the browser process on the host system.
  • The attacker can write or modify data on the host, including files and configuration accessible under the user's permissions.
  • The attacker can crash or destabilize processes outside the browser sandbox, causing service disruption on the affected host.

How HarborGuard Handles This

Available on HarborGuard: any image carrying a Chrome or Chromium binary older than 148.0.7778.216 is flagged automatically when the CVE is ingested, which occurs within minutes of publication. For customers with auto-remediation enabled, HarborGuard rebuilds the image at the patched version, runs regression tests, and opens a pull request against affected workloads; for high-severity issues, the median time from CVE publication to merged patch PR in auto-remediation environments is around 90 minutes. Where compliance policy requires manual approval, the finding is routed to the designated team inbox with full CVSS context and a ready-to-merge rebuild attached. Customers who cannot immediately deploy the patched image should consider network-policy controls that restrict which workloads can load arbitrary external HTML content, reducing exposure while the patch is validated.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H