CVE-2026-9899: Use after free in ANGLE in Google Chrome prior to 148
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
A use-after-free vulnerability exists in ANGLE, the graphics abstraction layer used by Google Chrome prior to version 148.0.7778.216. The flaw is reachable over the network, requires no authentication, but does require a victim to visit a crafted HTML page, and is harder to exploit reliably due to high attack complexity. An attacker who has already compromised the Chrome renderer process can exploit this flaw to escape the browser sandbox, gaining full confidentiality, integrity, and availability impact on the host. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version of Chrome.
HarborGuard Coverage
Detection for CVE-2026-9899 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of publication from upstream feeds, covering both public base images and custom-built images that bundle Chrome. Any image containing a Chrome version below 148.0.7778.216 is flagged automatically as it enters a monitored registry or CI pipeline.
AvailableHarborGuard surfaces CVE-2026-9899 with its CVSS v3.1 score of 8.3 (HIGH) and applies per-environment compliance policy weighting to determine urgency, escalating alerts to the appropriate team inbox within each customer organization based on configured routing rules.
AvailableA patched-image rebuild at Chrome 148.0.7778.216 is available on HarborGuard for any environment where an affected image is detected. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite against the updated image, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network by directing a victim to a crafted HTML page hosted on an attacker-controlled server.
- AuthenticationNot required
No account or credentials are needed; the attack is launched against any user who visits the malicious page.
- Victim interactionRequired
The victim must actively open or be redirected to a crafted HTML page, making social engineering or a malicious ad a necessary part of the attack chain.
- Attack complexityDetail
Attack complexity is rated High, meaning the attacker must have already compromised the Chrome renderer process before this flaw can be used to escape the sandbox, introducing a significant prerequisite.
Blast Radius
- A successful exploit escapes the Chrome sandbox, giving the attacker code execution outside the browser's restricted process.
- The attacker reads sensitive data accessible to the browser process, including stored credentials, cookies, and session tokens.
- The attacker writes or modifies files and data accessible to the compromised user account on the host system.
- The attacker can crash or destabilize the host process, disrupting the affected service or user session.
How HarborGuard Handles This
Available on HarborGuard: images containing Chrome below 148.0.7778.216 are flagged at ingest, and a rebuild pinned to the fixed version 148.0.7778.216 is made available immediately. For customers who opt into auto-remediation, HarborGuard rebuilds the image, runs regression tests, and opens a pull request against affected workloads; for high-severity issues, the median time from CVE publication to a merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual review, the flagged finding is routed to the configured team inbox with the CVSS score, affected image list, and recommended fix version attached for faster triage.
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H