HarborGuard / CVE
Back to search
HIGHCVE-2026-9901Published Modified CNA Chrome

CVE-2026-9901: Use after free in ANGLE in Google Chrome prior to 148

Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

Use-after-free in ANGLE (Chrome's graphics abstraction layer) in Google Chrome versions prior to 148.0.7778.216. The vulnerability is reachable over the network, requires no authentication, but does require a victim to interact with a crafted HTML page, and is exploitable only by an attacker who has already compromised the Chrome renderer process. Successful exploitation allows the attacker to execute arbitrary code in the context of the browser process. A patched-image rebuild at 148.0.7778.216 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection of CVE-2026-9901 is available across every HarborGuard environment; the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle or vendor Google Chrome.

Available
Triage

HarborGuard scores this CVE at 7.5 HIGH using the published CVSS v3.1 vector and weighs it against each environment's compliance policy to route alerts to the appropriate team inbox within each customer organization.

Available
Patch

A patched-image rebuild pinned to Chrome 148.0.7778.216 becomes available on HarborGuard for any image found to carry an affected version. For customers with auto-remediation enabled, HarborGuard runs the rebuild, executes a regression test suite, and opens a pull request against affected workloads.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing the victim to a crafted HTML page hosted remotely.

  • AuthenticationNot required

    No account or credentials on the target system are needed to deliver the malicious page.

  • Victim interactionRequired

    The victim must open a crafted HTML page, making this a social-engineering-dependent attack that requires the user to visit or be redirected to attacker-controlled content.

  • Attack complexityDetail

    Exploitation is rated High complexity because it requires a prior renderer process compromise as a precondition, introducing a significant multi-stage dependency before this vulnerability can be reached.

Blast Radius

  • An attacker gains arbitrary code execution in the browser process, able to run any instructions with the privileges of the Chrome process on the victim host.
  • Confidential data accessible to the browser (stored credentials, session tokens, browsing history, local files reachable by Chrome) is exposed to the attacker.
  • The attacker can write or modify data accessible to the browser process, including cached content and files within Chrome's working directories.
  • The browser process can be crashed or made unresponsive, disrupting the user's session and any dependent browser-based workflows.

How HarborGuard Handles This

Available on HarborGuard: images containing Google Chrome below 148.0.7778.216 are flagged automatically as new scan results arrive. Where compliance policy permits, a rebuilt image at the fixed version (148.0.7778.216) is prepared and, for customers who opt into auto-remediation, paired with a regression test run and a pull request opened against affected workloads. For high-severity issues, the median time from CVE publication to a merged patch PR is around 90 minutes in environments with auto-remediation enabled. If your policy requires manual approval, the rebuilt image and CVSS detail are surfaced in the HarborGuard dashboard for reviewer sign-off. Because this vulnerability requires a pre-compromised renderer as a stepping stone, teams may also consider network-policy controls that limit outbound connectivity from browser-running containers as a compensating measure while upgrades are staged.

See how HarborGuard automates this

Metrics

CVSS v3.1
7.5
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H