HarborGuard / CVE
Back to search
HIGHCVE-2026-9941Published Modified CNA Chrome

CVE-2026-9941: Use after free in ANGLE in Google Chrome prior to 148

Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability in ANGLE, the graphics abstraction layer used by Google Chrome, allows a remote attacker to execute arbitrary code inside the browser sandbox by tricking a user into visiting a crafted HTML page. The vulnerability is reachable over the network and requires no authentication, only that the victim opens a malicious page. Successful exploitation gives the attacker code execution within the Chrome sandbox, which may serve as a stepping stone to a full browser escape. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected Chrome version.

HarborGuard Coverage

Detection

Detection capability is available across every HarborGuard environment: CVE-2026-9941 is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Chrome or Chromium. Any image in a customer registry or CI pipeline running a Chrome version below 148.0.7778.216 is flagged automatically.

Available
Triage

HarborGuard scores this CVE at CVSS 8.8 (HIGH) and surfaces it accordingly in each customer environment, weighted against that environment's compliance policy to determine urgency. Triage results are routed to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild pinned to Chrome 148.0.7778.216 becomes available on HarborGuard the moment the fix version is resolvable from the upstream advisory. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite against it, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by hosting a crafted HTML page that the victim's browser fetches remotely.

  • AuthenticationNot required

    No account, credential, or prior session is needed; any user browsing to the malicious page is a valid target.

  • Victim interactionRequired

    The victim must open or be redirected to the attacker-controlled HTML page, making this a social-engineering or drive-by delivery scenario.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental preconditions.

Blast Radius

  • Attacker executes arbitrary code inside the Chrome renderer sandbox, gaining full control of the sandboxed process.
  • Confidential data processed by the renderer, including page content, stored credentials surfaced by autofill, and session tokens, is readable by the attacker.
  • The attacker can modify data within the sandboxed context, including intercepting or altering network requests issued by the page.
  • Sandbox code execution is a recognized prerequisite for chained browser-escape exploits, making this a high-value initial foothold.

How HarborGuard Handles This

Available on HarborGuard: CVE-2026-9941 is matched against any image that bundles Chrome or Chromium below version 148.0.7778.216 as soon as the advisory is ingested. Given the HIGH severity and the availability of a vendor fix, a patched-image rebuild at 148.0.7778.216 is queued automatically on HarborGuard. For customers who opt into auto-remediation, the median time from CVE publication to a merged patch PR for high-severity issues is around 90 minutes, covering the rebuild, regression run, and pull request opened against affected workloads. Where compliance policy requires manual approval, the rebuilt image and test results are staged and waiting for engineer sign-off. Customers who cannot immediately update are advised to apply network-policy controls that restrict which internal services can be reached from browser-running hosts, reducing the potential blast radius of a sandbox escape.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H