HarborGuard / CVE
Back to search
HIGHCVE-2026-9904Published Modified CNA Chrome

CVE-2026-9904: Use after free in ANGLE in Google Chrome prior to 148

Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability exists in ANGLE, the graphics translation layer bundled with Google Chrome prior to version 148.0.7778.216. The flaw is reachable over the network, requires no authentication, but does require the victim to load a crafted HTML page. Successful exploitation lets a remote attacker escape Chrome's sandbox, gaining code execution outside the browser's restricted process. A patched-image rebuild at 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-9904 is available across every HarborGuard environment - the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle a Chrome or Chromium runtime.

Available
Triage

HarborGuard scores this issue at 8.3 HIGH (CVSS v3.1) and is capable of weighting that score against each environment's compliance policy to prioritize routing - ensuring the finding reaches the appropriate team inbox within each customer org without manual triage steps.

Available
Patch

A patched-image rebuild targeting Chrome 148.0.7778.216 is available on HarborGuard for any environment found running an affected version. For customers who opt into auto-remediation, HarborGuard is capable of triggering the rebuild, running a regression test suite, and opening a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing the victim to a crafted HTML page hosted on an attacker-controlled server.

  • AuthenticationNot required

    No account or credential is required; the attacker needs only to get the victim to load the malicious page.

  • Victim interactionRequired

    The victim must actively open the crafted HTML page, making this a social-engineering vector (e.g., a phishing link or malicious ad).

  • Attack complexityDetail

    Exploitation is rated High complexity, meaning the attacker likely depends on specific memory layout conditions or timing factors that are not fully under attacker control on every attempt.

Blast Radius

  • A successful exploit escapes Chrome's sandbox, giving the attacker code execution in the context of the browser process on the victim's host.
  • With sandbox escape, the attacker can read files and credentials accessible to the user running Chrome, including stored session tokens and profile data.
  • The attacker can write or modify files on the host filesystem within the user's permission scope, enabling persistence or further lateral movement.
  • The attacker can crash or disrupt the browser process and any dependent services running under the same user account.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-9904 activates as soon as the CVE is ingested, with image matching covering any container that packages a Chrome or Chromium binary below 148.0.7778.216. Where compliance policy permits, HarborGuard can rebuild affected images at the patched version, run a regression test pass, and open a pull request against affected workloads - for environments with auto-remediation enabled, the median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes. For environments where auto-remediation is not enabled, the finding is surfaced in the HarborGuard dashboard with fix-version detail so engineering teams can act directly. Given the sandbox-escape severity and the victim-interaction requirement, teams that cannot patch immediately should also consider network-policy controls that restrict which internal domains can serve Chrome-rendered content inside containerized workloads.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H