CVE-2026-9922: Use after free in GPU in Google Chrome on Mac prior to 148
Use after free in GPU in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
A use-after-free vulnerability in the GPU component of Google Chrome on macOS affects all Chrome versions prior to 148.0.7778.216. The flaw is reachable over the network but requires the attacker to have already compromised the renderer process and to trick a user into visiting a crafted HTML page. Successful exploitation enables arbitrary code execution on the affected host. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection of CVE-2026-9922 is available across every HarborGuard environment, with the CVE matched against images in customer registries and CI/CD pipelines within minutes of upstream publication. Coverage extends to custom-built images that bundle a Chromium or Chrome binary, not just official upstream base images.
AvailableHarborGuard scores this CVE at 7.5 HIGH using the published CVSS v3.1 vector, and per-environment compliance policy weighting is applied to adjust priority based on each customer org's risk tolerance. Triage results are routed to the appropriate team inbox within each customer environment based on image ownership and policy configuration.
AvailableA patched-image rebuild at Chrome 148.0.7778.216 is available on HarborGuard for any environment found running an affected version. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite against the updated image, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network by directing a victim to a crafted HTML page hosted remotely.
- AuthenticationNot required
No account or credential is needed on the targeted system; the attacker operates as an unauthenticated remote party.
- Victim interactionRequired
The victim must visit a crafted HTML page, meaning the attacker must socially engineer or redirect the user to attacker-controlled content.
- Attack complexityDetail
Exploitation is rated high complexity because the attacker must have already compromised the renderer process before triggering the GPU use-after-free, introducing a significant pre-condition.
Blast Radius
- An attacker who triggers the vulnerability executes arbitrary code in the context of the Chrome process on the victim's Mac.
- Confidential data accessible to the browser process, including stored credentials, session tokens, and locally cached files, can be read.
- An attacker can write to or modify data reachable by the browser process, including browser storage and any files the process has write access to.
- The browser process can be crashed or forced into an unrecoverable state, denying service to the user.
How HarborGuard Handles This
Available on HarborGuard: any image in a customer registry or pipeline that bundles a Chrome or Chromium binary below version 148.0.7778.216 is flagged automatically when the CVE feed is ingested. For customers who opt into auto-remediation, HarborGuard initiates a patched rebuild at 148.0.7778.216, runs regression tests against the rebuilt image, and opens a pull request against affected workloads; for high-severity issues, median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual review, the CVE is routed to the designated team inbox with the full CVSS context and affected image list attached, so the team can act without additional triage work.
Metrics
- CVSS v3.1
- 7.5
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H