HarborGuard / CVE
Back to search
HIGHCVE-2026-9905Published Modified CNA Chrome

CVE-2026-9905: Use after free in Accessibility in Google Chrome on Windows prior to 148

Use after free in Accessibility in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability exists in the Accessibility component of Google Chrome on Windows in versions prior to 148.0.7778.216. The flaw is reachable over the network but requires the attacker to have already compromised the renderer process and requires the victim to interact with a crafted HTML page; successful exploitation enables a sandbox escape, granting the attacker capabilities outside the browser sandbox with high impact on confidentiality, integrity, and availability. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection of CVE-2026-9905 is available across every HarborGuard environment, with the CVE ingested from upstream feeds within minutes of publication and matched against customer images in both registries and active CI/CD pipelines, including custom-built images that bundle Chrome on Windows base layers.

Available
Triage

HarborGuard is capable of scoring this CVE at 8.3 HIGH using the CVSS v3.1 vector, with per-environment compliance policy weighting applied to prioritize routing; triage results are delivered to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild at Chrome 148.0.7778.216 is available on HarborGuard for any environment running an affected version. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite against the updated image, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the crafted HTML page over the network, so the targeted Chrome instance must be reachable and browsing attacker-controlled or attacker-influenced content.

  • AuthenticationNot required

    No account or credentials are required; the attack is initiated by luring a user to a crafted page without any prior authentication to the target system.

  • Victim interactionRequired

    The victim must visit or be redirected to a crafted HTML page, making a social-engineering or drive-by-redirect step necessary for exploitation.

  • Attack complexityDetail

    Attack complexity is high because the attacker must first have compromised the Chrome renderer process before the use-after-free can be leveraged for a sandbox escape, introducing a significant prerequisite condition.

Blast Radius

  • An attacker who achieves the sandbox escape gains code execution outside the Chrome sandbox, reading files and credentials accessible to the browser process on the Windows host.
  • The attacker can write or modify data on the host filesystem or in other processes accessible from outside the sandbox.
  • The attacker can crash or destabilize the browser process or other host processes, disrupting service for the affected user.
  • Because the scope change (S:C) is present in the CVSS vector, impact extends beyond the browser itself to other components sharing the same host.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-9905 is active across all connected registries and pipelines, matching any image that packages a vulnerable Chrome build on a Windows base layer. For environments where a patched rebuild is applicable, HarborGuard makes a rebuilt image at version 148.0.7778.216 available as soon as the upstream fix is confirmed. For customers who opt into auto-remediation, HarborGuard performs the image rebuild, executes a regression test run against the updated artifact, and opens a pull request targeting affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuilt image and triage report are queued for reviewer action without any automated merge.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
CVE-2026-9905: Use after free in Accessibility in Google Chrome on Windows prior to 148 | HarborGuard CVE