HarborGuard / CVE
Back to search
HIGHCVE-2026-9897Published Modified CNA Chrome

CVE-2026-9897: Use after free in DOM in Google Chrome prior to 148

Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

Use-after-free in the DOM component of Google Chrome prior to version 148.0.7778.216 allows a remote attacker to execute arbitrary code inside the browser sandbox by convincing a user to visit a crafted HTML page. The vulnerability is reachable over the network and requires no authentication, though it does require the victim to open a malicious page. Successful exploitation gives the attacker arbitrary code execution within the Chrome sandbox. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version of Chrome.

HarborGuard Coverage

Detection

Detection of CVE-2026-9897 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle Chrome or Chromium as a dependency.

Available
Triage

HarborGuard triage capability surfaces this CVE with its CVSS v3.1 score of 8.8 (HIGH), applies per-environment compliance policy weighting, and routes the finding to the appropriate team inbox within each customer organization based on configured severity thresholds.

Available
Patch

A patched-image rebuild at Chrome 148.0.7778.216 becomes available on HarborGuard for any image found to include an affected Chrome version. For customers who opt into auto-remediation, HarborGuard triggers the rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing the victim to a remotely hosted crafted HTML page, so the Chrome instance must be reachable through normal web browsing.

  • AuthenticationNot required

    No account or credentials are required on the targeted service; the attacker only needs to serve a malicious page.

  • Victim interactionRequired

    The victim must open or be redirected to a crafted HTML page, requiring a social-engineering step such as a phishing link or malicious ad.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and requires no special race conditions, memory layout dependencies, or other environmental factors to succeed.

Blast Radius

  • Attacker executes arbitrary code inside the Chrome renderer sandbox, gaining control of the sandboxed process.
  • Confidential data processed or displayed in the affected tab, including session tokens, form inputs, and rendered page content, is exposed to the attacker.
  • The attacker can tamper with page content, inject scripts, or use the sandboxed foothold as a stepping stone toward a sandbox-escape chain.
  • The affected Chrome renderer process can be crashed or destabilized, disrupting the browsing session for the targeted user.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-9897 activates as soon as the CVE is ingested, matching any image that packages Chrome or Chromium below version 148.0.7778.216. A rebuild at the fixed version is available for affected images once the upstream package is confirmed present. For customers who opt into auto-remediation, HarborGuard handles the full remediation loop: rebuild the image at the patched version, run regression tests, and open a pull request against affected workloads. For high-severity issues, the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy does not permit auto-remediation, HarborGuard flags the finding with its 8.8 CVSS score and routes it to the configured team inbox so engineers can act manually. Because exploitation requires only that a user visit a malicious page, prioritizing this patch in browser-bundling images or developer workstation base images is advisable.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H