CVE-2026-9904: Use after free in ANGLE in Google Chrome prior to 148
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
A use-after-free vulnerability exists in ANGLE, the graphics translation layer bundled with Google Chrome prior to version 148.0.7778.216. The flaw is reachable over the network, requires no authentication, but does require the victim to load a crafted HTML page. Successful exploitation lets a remote attacker escape Chrome's sandbox, gaining code execution outside the browser's restricted process. A patched-image rebuild at 148.0.7778.216 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection of CVE-2026-9904 is available across every HarborGuard environment - the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle a Chrome or Chromium runtime.
AvailableHarborGuard scores this issue at 8.3 HIGH (CVSS v3.1) and is capable of weighting that score against each environment's compliance policy to prioritize routing - ensuring the finding reaches the appropriate team inbox within each customer org without manual triage steps.
AvailableA patched-image rebuild targeting Chrome 148.0.7778.216 is available on HarborGuard for any environment found running an affected version. For customers who opt into auto-remediation, HarborGuard is capable of triggering the rebuild, running a regression test suite, and opening a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network by directing the victim to a crafted HTML page hosted on an attacker-controlled server.
- AuthenticationNot required
No account or credential is required; the attacker needs only to get the victim to load the malicious page.
- Victim interactionRequired
The victim must actively open the crafted HTML page, making this a social-engineering vector (e.g., a phishing link or malicious ad).
- Attack complexityDetail
Exploitation is rated High complexity, meaning the attacker likely depends on specific memory layout conditions or timing factors that are not fully under attacker control on every attempt.
Blast Radius
- A successful exploit escapes Chrome's sandbox, giving the attacker code execution in the context of the browser process on the victim's host.
- With sandbox escape, the attacker can read files and credentials accessible to the user running Chrome, including stored session tokens and profile data.
- The attacker can write or modify files on the host filesystem within the user's permission scope, enabling persistence or further lateral movement.
- The attacker can crash or disrupt the browser process and any dependent services running under the same user account.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-9904 activates as soon as the CVE is ingested, with image matching covering any container that packages a Chrome or Chromium binary below 148.0.7778.216. Where compliance policy permits, HarborGuard can rebuild affected images at the patched version, run a regression test pass, and open a pull request against affected workloads - for environments with auto-remediation enabled, the median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes. For environments where auto-remediation is not enabled, the finding is surfaced in the HarborGuard dashboard with fix-version detail so engineering teams can act directly. Given the sandbox-escape severity and the victim-interaction requirement, teams that cannot patch immediately should also consider network-policy controls that restrict which internal domains can serve Chrome-rendered content inside containerized workloads.
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H