CVE-2026-9897: Use after free in DOM in Google Chrome prior to 148
Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
Use-after-free in the DOM component of Google Chrome prior to version 148.0.7778.216 allows a remote attacker to execute arbitrary code inside the browser sandbox by convincing a user to visit a crafted HTML page. The vulnerability is reachable over the network and requires no authentication, though it does require the victim to open a malicious page. Successful exploitation gives the attacker arbitrary code execution within the Chrome sandbox. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version of Chrome.
HarborGuard Coverage
Detection of CVE-2026-9897 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle Chrome or Chromium as a dependency.
AvailableHarborGuard triage capability surfaces this CVE with its CVSS v3.1 score of 8.8 (HIGH), applies per-environment compliance policy weighting, and routes the finding to the appropriate team inbox within each customer organization based on configured severity thresholds.
AvailableA patched-image rebuild at Chrome 148.0.7778.216 becomes available on HarborGuard for any image found to include an affected Chrome version. For customers who opt into auto-remediation, HarborGuard triggers the rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network by directing the victim to a remotely hosted crafted HTML page, so the Chrome instance must be reachable through normal web browsing.
- AuthenticationNot required
No account or credentials are required on the targeted service; the attacker only needs to serve a malicious page.
- Victim interactionRequired
The victim must open or be redirected to a crafted HTML page, requiring a social-engineering step such as a phishing link or malicious ad.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and requires no special race conditions, memory layout dependencies, or other environmental factors to succeed.
Blast Radius
- Attacker executes arbitrary code inside the Chrome renderer sandbox, gaining control of the sandboxed process.
- Confidential data processed or displayed in the affected tab, including session tokens, form inputs, and rendered page content, is exposed to the attacker.
- The attacker can tamper with page content, inject scripts, or use the sandboxed foothold as a stepping stone toward a sandbox-escape chain.
- The affected Chrome renderer process can be crashed or destabilized, disrupting the browsing session for the targeted user.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-9897 activates as soon as the CVE is ingested, matching any image that packages Chrome or Chromium below version 148.0.7778.216. A rebuild at the fixed version is available for affected images once the upstream package is confirmed present. For customers who opt into auto-remediation, HarborGuard handles the full remediation loop: rebuild the image at the patched version, run regression tests, and open a pull request against affected workloads. For high-severity issues, the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy does not permit auto-remediation, HarborGuard flags the finding with its 8.8 CVSS score and routes it to the configured team inbox so engineers can act manually. Because exploitation requires only that a user visit a malicious page, prioritizing this patch in browser-bundling images or developer workstation base images is advisable.
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H