HarborGuard / CVE
Back to search
HIGHCVE-2026-9938Published Modified CNA Chrome

CVE-2026-9938: Inappropriate implementation in V8 in Google Chrome prior to 148

Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

An inappropriate implementation flaw in the V8 JavaScript engine affects Google Chrome versions prior to 148.0.7778.216. The vulnerability is reachable over the network and requires no authentication, though the victim must visit a crafted HTML page for the exploit to trigger. Successful exploitation gives a remote attacker arbitrary code execution inside the Chrome sandbox. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection for CVE-2026-9938 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of publication from upstream feeds, including custom-built images that bundle a Chrome or Chromium installation. Any image containing a Chrome version below 148.0.7778.216 is flagged automatically across both registry scans and active pipeline checks.

Available
Triage

Triage is available with a CVSS v3.1 score of 8.8 (HIGH), weighted against each customer environment's compliance policy to prioritize workloads where a browser component has external or user-facing exposure. Findings are routed to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild at Chrome 148.0.7778.216 becomes available on HarborGuard for any environment where an affected version is detected. For customers with auto-remediation enabled, HarborGuard performs the rebuild, runs a regression test suite against the updated image, and opens a pull request against affected workloads.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by luring the victim to a crafted HTML page, requiring the Chrome instance to have outbound or inbound web access.

  • AuthenticationNot required

    No credentials or account are needed; any unauthenticated visitor to the attacker-controlled page is a viable target.

  • Victim interactionRequired

    The victim must actively visit or be redirected to the crafted HTML page, making social engineering or malicious ad delivery the primary delivery mechanism.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental factors.

Blast Radius

  • A successful attacker executes arbitrary code within the Chrome renderer sandbox, gaining control of the JavaScript execution environment for that browsing context.
  • Confidentiality impact is high: the attacker reads data accessible to the renderer, including page content, stored credentials surfaced by autofill, and session tokens held in memory.
  • Integrity impact is high: the attacker modifies in-page data and can interact with web APIs to alter persisted state such as IndexedDB records or cached service-worker scripts.
  • Availability impact is high: the attacker crashes or hangs the affected renderer process, disrupting the user's session and any dependent background workers.

How HarborGuard Handles This

Available on HarborGuard: images containing Google Chrome below 148.0.7778.216 are matched against this CVE within minutes of feed ingestion and surfaced as HIGH-severity findings. A rebuilt image at the fixed version (148.0.7778.216) is available for affected environments. For customers who opt into auto-remediation, HarborGuard triggers the rebuild, executes a regression run against the updated image, and opens a pull request targeting affected workloads; for high-severity issues, the median time from CVE publication to a merged patch PR is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the finding is routed to the configured owner inbox with remediation guidance attached. Customers who cannot immediately update are advised to apply network-policy controls that restrict which container workloads can launch a browser process, and to gate any feature that embeds Chrome until the patched image is deployed.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H