HarborGuard / CVE
Back to search
HIGHCVE-2026-9936Published Modified CNA Chrome

CVE-2026-9936: Use after free in GFX in Google Chrome on Mac prior to 148

Use after free in GFX in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability in the GFX (graphics) component of Google Chrome on macOS affects all versions prior to 148.0.7778.216. The flaw is reachable over the network but requires the attacker to have already compromised the Chrome renderer process, and a victim must interact with a crafted HTML page. Successful exploitation enables a sandbox escape, giving the attacker code execution outside the browser sandbox with high impact to confidentiality, integrity, and availability. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: CVE-2026-9936 is ingested from upstream advisory feeds within minutes of publication and matched against all customer images in connected registries and CI pipelines, including custom-built images that bundle a Chrome or Chromium binary.

Available
Triage

HarborGuard scores this CVE at CVSS 8.3 (HIGH) and is capable of weighting that score against each environment's compliance policy to prioritize or escalate as appropriate, routing findings to the correct team inbox within the customer organization.

Available
Patch

A patched-image rebuild pinned to Chrome 148.0.7778.216 becomes available on HarborGuard once the upstream fix is confirmed. For customers who opt into auto-remediation, the pipeline rebuilds the affected image, runs a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the victim over the network by delivering a crafted HTML page, exposing the attack surface to any internet-accessible browser session.

  • AuthenticationNot required

    No authentication is required; the attacker does not need any account or credential on the target system.

  • Victim interactionRequired

    A victim must visit or otherwise interact with a crafted HTML page, meaning the attacker depends on a social-engineering or drive-by delivery step.

  • Attack complexityDetail

    Attack complexity is HIGH, meaning the attacker must first achieve renderer-process compromise before the use-after-free can be leveraged for a sandbox escape, introducing a significant prerequisite step.

Blast Radius

  • A successful attacker escapes the Chrome browser sandbox on macOS, gaining code-execution rights outside the renderer's restricted environment.
  • With sandbox escape achieved, the attacker reads files and data accessible to the browser process, including cookies, stored credentials, and local profile data.
  • The attacker can write to or modify files and system state reachable by the browser process user account.
  • The attacker can crash or destabilize the browser process and dependent services, causing denial of service to the affected session.

How HarborGuard Handles This

Available on HarborGuard: images containing a Chrome or Chromium binary older than 148.0.7778.216 on macOS base layers are flagged automatically as CVE-2026-9936 is matched during each ingest cycle. For customers who opt into auto-remediation, HarborGuard rebuilds the affected image at the patched version, runs a regression test pass, and opens a pull request against affected workloads; for HIGH-severity issues, the median time from CVE publication to a merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the finding is routed to the designated team inbox with the CVSS 8.3 score, fix version, and remediation context attached. Because this vulnerability requires a prior renderer compromise, customers should also consider defense-in-depth measures such as network-policy isolation for workloads embedding a Chrome binary and strict Content Security Policy headers on any internal tooling that renders HTML via a bundled Chromium.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H