CVE-2026-9900: Out of bounds write in ANGLE in Google Chrome prior to 148
Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
An out-of-bounds write vulnerability exists in ANGLE, the graphics-layer translation library embedded in Google Chrome versions prior to 148.0.7778.216. The flaw is reachable over the network but requires the attacker to have already compromised the Chrome renderer process and to trick a user into visiting a crafted HTML page; no authentication is needed. Successful exploitation enables a sandbox escape, giving the attacker code execution outside the browser sandbox with access to confidential data, the ability to tamper with system state, and the ability to disrupt service. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection of CVE-2026-9900 is available across every HarborGuard environment: the CVE is ingested from upstream advisory feeds within minutes of publication and matched against all customer images, including custom-built images that bundle a Chromium or Chrome runtime. No manual configuration is required for matching to occur.
AvailableHarborGuard scores this CVE at 8.3 HIGH using the published CVSS v3.1 vector and weights it against each customer environment's compliance policy, which can escalate or suppress routing priority. Triage findings are delivered to the team inbox configured for each customer organization based on the affected image owners.
AvailableA patched-image rebuild pinned to Chrome 148.0.7778.216 becomes available in HarborGuard as soon as the fix version is indexed. For customers who have opted into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network by directing the victim to a crafted HTML page served from a remote host.
- AuthenticationNot required
No account or credentials are needed; the attack is initiated from an unauthenticated network position.
- Victim interactionRequired
A user must visit or be redirected to the attacker-controlled HTML page, making social engineering or malicious ad injection the likely delivery mechanism.
- Attack complexityDetail
Exploitation is rated high complexity because the attacker must already have compromised the Chrome renderer process before the out-of-bounds write can be used for a sandbox escape, introducing a prerequisite chained step.
Blast Radius
- Reads memory outside the intended buffer, exposing sensitive in-process data such as credentials, session tokens, or page content from other origins.
- Writes attacker-controlled data outside bounds, allowing modification of memory structures and enabling code execution outside the Chrome sandbox.
- Crashes the affected Chrome process if exploit conditions are not precisely met, causing a denial of service for the browser session.
- Once sandbox escape is achieved, the attacker operates with the privileges of the browser process on the host, enabling access to local files and system resources.
How HarborGuard Handles This
Available on HarborGuard: detection against all images containing an affected Chrome or Chromium version is active the moment the CVE is indexed, with no manual setup needed. Where a customer's compliance policy permits auto-remediation, HarborGuard rebuilds the image at Chrome 148.0.7778.216, runs regression tests, and opens a PR against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled. For customers who review patches manually, the rebuilt image is staged and waiting in the HarborGuard registry view alongside the full CVSS detail, affected layer diff, and triage routing history. Given the sandbox-escape nature of this vulnerability, customers running Chrome-based container workloads (such as headless browser services or test automation runtimes) are encouraged to treat this as high priority and apply the rebuild promptly.
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H