CVE-2026-9947: Use after free in XML in Google Chrome prior to 148
Use after free in XML in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
Use-after-free vulnerability in the XML processing component of Google Chrome prior to version 148.0.7778.216 allows a remote attacker to exploit freed memory by luring a user to a crafted HTML page, requiring no authentication. Successful exploitation gives the attacker arbitrary code execution inside the Chrome sandbox, enabling full control of the renderer process. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle a Chrome or Chromium binary. Any image carrying a Chrome version below 148.0.7778.216 is flagged immediately.
AvailableHarborGuard scores this finding at CVSS 8.8 HIGH and is capable of weighting it further against each customer environment's compliance policy before routing the alert to the appropriate team inbox within that organization.
AvailableA patched-image rebuild at Chrome 148.0.7778.216 is available on HarborGuard for any environment running an affected version. For customers who opt into auto-remediation, HarborGuard can trigger a rebuild, run a regression test suite, and open a PR against affected workloads automatically; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes for environments with auto-remediation enabled.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network; the target browser must be able to reach and load the crafted HTML page, so the Chrome instance must have outbound network access or the user must visit an attacker-controlled URL.
- AuthenticationNot required
No account or credential is needed; the attacker only needs the victim to load a page, which requires no prior authentication relationship.
- Victim interactionRequired
The victim must navigate to or be redirected to a crafted HTML page, making this a social-engineering or drive-by delivery scenario.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other unpredictable environmental factors.
Blast Radius
- The attacker gains arbitrary code execution inside the Chrome renderer sandbox, allowing full control of that renderer process.
- Confidential data accessible to the renderer, including page content, session cookies, and stored credentials surfaced by the browser, can be read.
- The attacker can tamper with rendered content, inject scripts, or perform actions on behalf of the user within the compromised tab.
- The renderer process can be crashed or kept in an attacker-controlled state, disrupting the user's browsing session for that origin.
How HarborGuard Handles This
Available on HarborGuard: any image bundling Google Chrome below 148.0.7778.216 is flagged automatically within minutes of the CVE appearing in upstream feeds. For environments where a compliance policy permits auto-remediation, HarborGuard can rebuild the image at the patched version (148.0.7778.216), run a regression test pass, and open a pull request against affected workloads without manual intervention; for high-severity issues like this one, the median time from CVE publication to a merged patch PR is around 90 minutes. For environments that manage their own build pipelines, HarborGuard surfaces the finding with the exact version delta so engineers can prioritize and schedule the upgrade. If an immediate rebuild is not possible, consider isolating affected container workloads behind a network policy that restricts outbound browsing surfaces or disables Chrome-based rendering features via feature flags until the patched image is deployed.
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H