HarborGuard / CVE
Back to search
HIGHCVE-2026-9894Published Modified CNA Chrome

CVE-2026-9894: Use after free in GPU in Google Chrome prior to 148

Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability in the GPU component of Google Chrome allows a remote attacker who has already compromised the renderer process to escape the browser sandbox. The attacker reaches the vulnerable code over the network but requires the victim to interact with a crafted HTML page, and no authentication is needed. Successful exploitation grants the attacker full read, write, and crash capabilities beyond the sandbox boundary, enabling code execution at the host process level. A patched-image rebuild at Chrome 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-9894 is available across every HarborGuard environment, with the CVE ingested from upstream feeds within minutes of publication and matched against customer container images in registries and CI/CD pipelines. Coverage extends to custom-built images that bundle a Chromium or Chrome binary below version 148.0.7778.216.

Available
Triage

HarborGuard is capable of scoring this CVE at CVSS 8.3 (High) and weighting it against each environment's compliance policy to determine urgency. Triage routing routes findings to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild at Chrome 148.0.7778.216 is available on HarborGuard for any image found to carry an affected version. For customers who opt into auto-remediation, the pipeline performs the rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the crafted HTML page over the network, so the victim's browser must be reachable and browsing remote content.

  • AuthenticationNot required

    No account or credential of any kind is needed; the attack is launched from an unauthenticated remote position.

  • Victim interactionRequired

    The victim must open or navigate to a crafted HTML page, making social engineering or malicious ad delivery the typical delivery mechanism.

  • Attack complexityDetail

    Exploitation requires that the attacker has already compromised the renderer process, meaning this is a chained exploit with a high environmental prerequisite rather than a straightforward single-step attack.

Blast Radius

  • Attacker escapes the Chrome sandbox and executes arbitrary code in the host browser process outside of renderer isolation.
  • Attacker reads sensitive data accessible to the browser process, including stored credentials, session cookies, and local profile data.
  • Attacker writes or modifies files and browser state accessible to the host process user account.
  • Attacker can crash the browser process or destabilize the host application, causing denial of service.

How HarborGuard Handles This

Available on HarborGuard: detection is matched against images carrying any Chrome binary below 148.0.7778.216 as soon as the CVE enters the upstream feed. A patched-image rebuild at 148.0.7778.216 is available for affected images. For customers who opt into auto-remediation, HarborGuard performs the rebuild, executes a regression test run, and opens a pull request against affected workloads; for high-severity issues, the median time from CVE publication to a merged patch PR in auto-remediation-enabled environments is around 90 minutes. Because this vulnerability requires a pre-compromised renderer as a precondition, teams that cannot immediately update should consider network-policy controls that restrict outbound connections from container workloads running Chrome, limiting the attacker's ability to stage the renderer compromise that this sandbox escape depends on.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H