CVE-2026-9905: Use after free in Accessibility in Google Chrome on Windows prior to 148
Use after free in Accessibility in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
A use-after-free vulnerability exists in the Accessibility component of Google Chrome on Windows in versions prior to 148.0.7778.216. The flaw is reachable over the network but requires the attacker to have already compromised the renderer process and requires the victim to interact with a crafted HTML page; successful exploitation enables a sandbox escape, granting the attacker capabilities outside the browser sandbox with high impact on confidentiality, integrity, and availability. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for affected environments.
HarborGuard Coverage
Detection of CVE-2026-9905 is available across every HarborGuard environment, with the CVE ingested from upstream feeds within minutes of publication and matched against customer images in both registries and active CI/CD pipelines, including custom-built images that bundle Chrome on Windows base layers.
AvailableHarborGuard is capable of scoring this CVE at 8.3 HIGH using the CVSS v3.1 vector, with per-environment compliance policy weighting applied to prioritize routing; triage results are delivered to the appropriate team inbox within each customer organization based on configured ownership rules.
AvailableA patched-image rebuild at Chrome 148.0.7778.216 is available on HarborGuard for any environment running an affected version. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite against the updated image, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the crafted HTML page over the network, so the targeted Chrome instance must be reachable and browsing attacker-controlled or attacker-influenced content.
- AuthenticationNot required
No account or credentials are required; the attack is initiated by luring a user to a crafted page without any prior authentication to the target system.
- Victim interactionRequired
The victim must visit or be redirected to a crafted HTML page, making a social-engineering or drive-by-redirect step necessary for exploitation.
- Attack complexityDetail
Attack complexity is high because the attacker must first have compromised the Chrome renderer process before the use-after-free can be leveraged for a sandbox escape, introducing a significant prerequisite condition.
Blast Radius
- An attacker who achieves the sandbox escape gains code execution outside the Chrome sandbox, reading files and credentials accessible to the browser process on the Windows host.
- The attacker can write or modify data on the host filesystem or in other processes accessible from outside the sandbox.
- The attacker can crash or destabilize the browser process or other host processes, disrupting service for the affected user.
- Because the scope change (S:C) is present in the CVSS vector, impact extends beyond the browser itself to other components sharing the same host.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-9905 is active across all connected registries and pipelines, matching any image that packages a vulnerable Chrome build on a Windows base layer. For environments where a patched rebuild is applicable, HarborGuard makes a rebuilt image at version 148.0.7778.216 available as soon as the upstream fix is confirmed. For customers who opt into auto-remediation, HarborGuard performs the image rebuild, executes a regression test run against the updated artifact, and opens a pull request targeting affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuilt image and triage report are queued for reviewer action without any automated merge.
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H