CVE-2026-9927: Use after free in ANGLE in Google Chrome prior to 148
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
A use-after-free vulnerability in ANGLE, the graphics abstraction layer used by Google Chrome, allows a remote attacker to execute arbitrary code inside Chrome's sandbox by luring a victim to a crafted HTML page. The flaw is reachable over the network and requires no authentication, only a single user interaction (visiting a malicious page). Successful exploitation gives the attacker code execution within the Chrome renderer sandbox, which can be chained with a sandbox-escape to achieve full process compromise. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection of CVE-2026-9927 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle a Chromium or Chrome binary. Any image with a Chrome version below 148.0.7778.216 is flagged automatically.
AvailableHarborGuard scores this CVE at CVSS 8.8 (HIGH) and weights it against each environment's compliance policy to determine urgency and routing. Triage findings are delivered to the appropriate team inbox within each customer organization based on image ownership and policy configuration.
AvailableA patched-image rebuild at Chrome 148.0.7778.216 becomes available on HarborGuard for every environment where an affected image is detected. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network; the target Chrome instance must be able to reach attacker-controlled or compromised web content.
- AuthenticationNot required
No account, credential, or prior access is needed; any anonymous user browsing the web is a valid target.
- Victim interactionRequired
The victim must visit a crafted HTML page, making this a social-engineering or malvertising vector that requires one deliberate or tricked navigation action.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layout, or other environmental preconditions.
Blast Radius
- The attacker executes arbitrary code inside the Chrome renderer sandbox, gaining full control over the renderer process.
- Confidentiality is fully compromised within the sandbox: the attacker reads DOM content, stored credentials surfaced by autofill, and any in-memory page data.
- Integrity is fully compromised within the sandbox: the attacker modifies page content, injects scripts, and manipulates network requests originating from the renderer.
- The affected Chrome renderer process can be crashed or destabilized, disrupting the user's browsing session for any open tab handled by that renderer.
How HarborGuard Handles This
Available on HarborGuard: images containing Chrome below 148.0.7778.216 are automatically identified and flagged as HIGH severity upon CVE ingestion. For customers with auto-remediation enabled, HarborGuard rebuilds the image at the patched version, executes a regression run, and opens a pull request against affected workloads; for HIGH-severity issues the median time from CVE publication to a merged patch PR in auto-remediation environments is around 90 minutes. For customers who review patches manually, HarborGuard surfaces the rebuild candidate in the remediation queue with CVSS score, affected layer, and fix version pre-populated. Because ANGLE is a graphics subsystem used inside the renderer sandbox, teams that cannot immediately rebuild should consider restricting or disabling GPU-process acceleration in containerized Chrome deployments as a compensating control until the patched image is promoted.
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H