CVE-2026-9936: Use after free in GFX in Google Chrome on Mac prior to 148
Use after free in GFX in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
A use-after-free vulnerability in the GFX (graphics) component of Google Chrome on macOS affects all versions prior to 148.0.7778.216. The flaw is reachable over the network but requires the attacker to have already compromised the Chrome renderer process, and a victim must interact with a crafted HTML page. Successful exploitation enables a sandbox escape, giving the attacker code execution outside the browser sandbox with high impact to confidentiality, integrity, and availability. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for affected environments.
HarborGuard Coverage
Detection is available across every HarborGuard environment: CVE-2026-9936 is ingested from upstream advisory feeds within minutes of publication and matched against all customer images in connected registries and CI pipelines, including custom-built images that bundle a Chrome or Chromium binary.
AvailableHarborGuard scores this CVE at CVSS 8.3 (HIGH) and is capable of weighting that score against each environment's compliance policy to prioritize or escalate as appropriate, routing findings to the correct team inbox within the customer organization.
AvailableA patched-image rebuild pinned to Chrome 148.0.7778.216 becomes available on HarborGuard once the upstream fix is confirmed. For customers who opt into auto-remediation, the pipeline rebuilds the affected image, runs a regression test suite, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker must reach the victim over the network by delivering a crafted HTML page, exposing the attack surface to any internet-accessible browser session.
- AuthenticationNot required
No authentication is required; the attacker does not need any account or credential on the target system.
- Victim interactionRequired
A victim must visit or otherwise interact with a crafted HTML page, meaning the attacker depends on a social-engineering or drive-by delivery step.
- Attack complexityDetail
Attack complexity is HIGH, meaning the attacker must first achieve renderer-process compromise before the use-after-free can be leveraged for a sandbox escape, introducing a significant prerequisite step.
Blast Radius
- A successful attacker escapes the Chrome browser sandbox on macOS, gaining code-execution rights outside the renderer's restricted environment.
- With sandbox escape achieved, the attacker reads files and data accessible to the browser process, including cookies, stored credentials, and local profile data.
- The attacker can write to or modify files and system state reachable by the browser process user account.
- The attacker can crash or destabilize the browser process and dependent services, causing denial of service to the affected session.
How HarborGuard Handles This
Available on HarborGuard: images containing a Chrome or Chromium binary older than 148.0.7778.216 on macOS base layers are flagged automatically as CVE-2026-9936 is matched during each ingest cycle. For customers who opt into auto-remediation, HarborGuard rebuilds the affected image at the patched version, runs a regression test pass, and opens a pull request against affected workloads; for HIGH-severity issues, the median time from CVE publication to a merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the finding is routed to the designated team inbox with the CVSS 8.3 score, fix version, and remediation context attached. Because this vulnerability requires a prior renderer compromise, customers should also consider defense-in-depth measures such as network-policy isolation for workloads embedding a Chrome binary and strict Content Security Policy headers on any internal tooling that renders HTML via a bundled Chromium.
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H