HarborGuard / CVE
Back to search
HIGHCVE-2026-9949Published Modified CNA Chrome

CVE-2026-9949: Use after free in Core in Google Chrome on Windows prior to 148

Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability affects the Core component of Google Chrome on Windows in versions prior to 148.0.7778.216. The flaw is reachable over the network but requires the attacker to have already compromised the Chrome renderer process; a victim must interact with a crafted HTML page to trigger the condition. Successful exploitation allows the attacker to escape Chrome's sandbox, gaining execution capabilities beyond the browser's isolated environment. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-9949 is available across every HarborGuard environment, with CVE feeds ingested within minutes of publication and matched against images in customer registries and CI/CD pipelines. Coverage extends to custom-built images that bundle a Chromium or Chrome binary, not just official upstream base images.

Available
Triage

HarborGuard is capable of scoring this CVE at 8.3 HIGH (CVSS v3.1) and weighting that score against each environment's compliance policy to surface it at the appropriate severity tier. Routing to the correct team inbox within a customer organization is handled automatically based on per-environment configuration.

Available
Patch

A patched-image rebuild at Chrome 148.0.7778.216 becomes available on HarborGuard for any image found to contain an affected version. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite against it, and opens a pull request against affected workloads.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network, requiring the victim's browser to reach or load attacker-controlled content.

  • AuthenticationNot required

    No account or credentials are needed; the attacker operates as an anonymous remote party.

  • Victim interactionRequired

    The victim must visit or be directed to a crafted HTML page, making this a social-engineering or drive-by-delivery scenario.

  • Attack complexityDetail

    Exploitation requires the renderer process to already be compromised, introducing a chained precondition that depends on a prior exploit step or environmental factor.

Blast Radius

  • Attacker escapes the Chrome sandbox and executes code outside the browser's isolated process, breaking the primary containment boundary on the host.
  • With sandbox escape achieved, the attacker reads files and credentials accessible to the browser process user account on the Windows host.
  • The attacker writes or modifies files and persisted data within the scope of that user account.
  • The attacker can crash or disrupt the Chrome process and any dependent services running under the same session.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-9949 activates within minutes of CVE publication for any image containing a Chrome binary below 148.0.7778.216. Where compliance policy permits, a rebuild against the patched version is queued automatically; for customers with auto-remediation enabled, HarborGuard also runs a regression test pass and opens a PR against affected workloads, with a median time from CVE publication to merged patch PR of around 90 minutes for high-severity issues in those environments. Because this vulnerability requires a compromised renderer as a prerequisite, teams that cannot immediately update should also consider restricting network egress from container workloads running Chrome-based tooling and auditing which pipelines embed a Chrome binary, to reduce the window of exposure while the rebuild is staged.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H