HarborGuard / CVE
Back to search
HIGHCVE-2026-9940Published Modified CNA Chrome

CVE-2026-9940: Heap buffer overflow in ANGLE in Google Chrome prior to 148

Heap buffer overflow in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A heap buffer overflow affects the ANGLE graphics layer in Google Chrome versions prior to 148.0.7778.216. The vulnerability is reachable over the network and requires no authentication, but does require a user to visit a crafted HTML page. Successful exploitation gives an attacker full read, write, and availability impact on the affected process, enabling data theft, content tampering, or a crash. A patched-image rebuild at 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle a Chromium or Chrome dependency.

Available
Triage

Affected images are scored at CVSS 8.8 (HIGH), and HarborGuard surfaces this severity alongside per-environment compliance policy weighting to route the finding to the appropriate team inbox within each customer organization.

Available
Patch

A patched-image rebuild at Chrome 148.0.7778.216 is available on HarborGuard for any environment scanning an image that contains an affected Chrome version. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite against the updated image, and opens a pull request against affected workloads.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by luring the target to a crafted HTML page hosted remotely.

  • AuthenticationNot required

    No account or credential is needed; the attacker interacts with the browser as an anonymous remote party.

  • Victim interactionRequired

    The target user must navigate to or be redirected to the attacker-controlled HTML page for the overflow to trigger.

  • Attack complexityDetail

    Exploitation is reliable and condition-free once the victim loads the page; no race condition or special memory layout is required.

Blast Radius

  • Reads process memory accessible to the Chrome renderer, exposing session tokens, cached credentials, or in-memory page content.
  • Writes arbitrary data into heap memory, allowing an attacker to corrupt renderer state or pivot toward code execution within the sandboxed process.
  • Crashes the affected Chrome renderer process, causing an immediate denial of service for the browsing session.
  • Combined high confidentiality, integrity, and availability impact means a single successful exploit can simultaneously exfiltrate data, tamper with rendered content, and terminate the process.

How HarborGuard Handles This

Available on HarborGuard: images containing Google Chrome prior to 148.0.7778.216 are flagged at HIGH severity the moment the CVE is ingested, typically within minutes of publication. For customers who opt into auto-remediation, HarborGuard rebuilds the image at the patched version, runs a regression test suite, and opens a pull request against affected workloads; for HIGH-severity issues the median time from CVE publication to merged patch PR in auto-remediation-enabled environments is around 90 minutes. Where compliance policy requires manual review before patching, the finding is routed to the designated inbox with CVSS score, vector breakdown, and affected image list attached. Customers who need to gate on a formal approval cycle can combine HarborGuard network-policy isolation recommendations (restricting outbound renderer access) as a compensating control while the patch PR is in review.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H