HarborGuard / CVE
Back to search
HIGHCVE-2026-9922Published Modified CNA Chrome

CVE-2026-9922: Use after free in GPU in Google Chrome on Mac prior to 148

Use after free in GPU in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability in the GPU component of Google Chrome on macOS affects all Chrome versions prior to 148.0.7778.216. The flaw is reachable over the network but requires the attacker to have already compromised the renderer process and to trick a user into visiting a crafted HTML page. Successful exploitation enables arbitrary code execution on the affected host. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-9922 is available across every HarborGuard environment, with the CVE matched against images in customer registries and CI/CD pipelines within minutes of upstream publication. Coverage extends to custom-built images that bundle a Chromium or Chrome binary, not just official upstream base images.

Available
Triage

HarborGuard scores this CVE at 7.5 HIGH using the published CVSS v3.1 vector, and per-environment compliance policy weighting is applied to adjust priority based on each customer org's risk tolerance. Triage results are routed to the appropriate team inbox within each customer environment based on image ownership and policy configuration.

Available
Patch

A patched-image rebuild at Chrome 148.0.7778.216 is available on HarborGuard for any environment found running an affected version. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite against the updated image, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by directing a victim to a crafted HTML page hosted remotely.

  • AuthenticationNot required

    No account or credential is needed on the targeted system; the attacker operates as an unauthenticated remote party.

  • Victim interactionRequired

    The victim must visit a crafted HTML page, meaning the attacker must socially engineer or redirect the user to attacker-controlled content.

  • Attack complexityDetail

    Exploitation is rated high complexity because the attacker must have already compromised the renderer process before triggering the GPU use-after-free, introducing a significant pre-condition.

Blast Radius

  • An attacker who triggers the vulnerability executes arbitrary code in the context of the Chrome process on the victim's Mac.
  • Confidential data accessible to the browser process, including stored credentials, session tokens, and locally cached files, can be read.
  • An attacker can write to or modify data reachable by the browser process, including browser storage and any files the process has write access to.
  • The browser process can be crashed or forced into an unrecoverable state, denying service to the user.

How HarborGuard Handles This

Available on HarborGuard: any image in a customer registry or pipeline that bundles a Chrome or Chromium binary below version 148.0.7778.216 is flagged automatically when the CVE feed is ingested. For customers who opt into auto-remediation, HarborGuard initiates a patched rebuild at 148.0.7778.216, runs regression tests against the rebuilt image, and opens a pull request against affected workloads; for high-severity issues, median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual review, the CVE is routed to the designated team inbox with the full CVSS context and affected image list attached, so the team can act without additional triage work.

See how HarborGuard automates this

Metrics

CVSS v3.1
7.5
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H