HarborGuard / CVE
Back to search
HIGHCVE-2026-9951Published Modified CNA Chrome

CVE-2026-9951: Use after free in UI in Google Chrome prior to 148

Use after free in UI in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability in the UI component of Google Chrome affects all versions prior to 148.0.7778.216. The flaw is reachable over the network but requires a victim to interact with a crafted HTML page; no authentication is needed. Successful exploitation allows a remote attacker to escape Chrome's sandbox, gaining the ability to read sensitive data, modify files, and crash processes outside the browser's normal security boundary. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection of CVE-2026-9951 is available across every HarborGuard environment, with the CVE matched against images in customer registries and CI/CD pipelines within minutes of upstream publication. Coverage extends to custom-built images that bundle or depend on Google Chrome, not only official base images.

Available
Triage

HarborGuard can score this finding at CVSS 8.3 (High) and weight it against each customer environment's compliance policy before routing the alert to the appropriate team inbox. Per-environment context, such as whether Chrome is exposed in a public-facing container, is factored into prioritization.

Available
Patch

A patched-image rebuild at Chrome 148.0.7778.216 becomes available through HarborGuard once the fix version is confirmed in the upstream feed. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite, and opens a PR against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must be able to reach the target over the network, delivering the crafted HTML page through a standard browser request.

  • AuthenticationNot required

    No account or credential is needed; any unauthenticated remote attacker can attempt the exploit.

  • Victim interactionRequired

    A victim must visit or be redirected to the attacker-controlled HTML page, making this a social-engineering-dependent attack.

  • Attack complexityDetail

    Exploitation is rated High complexity, meaning the attacker must account for race conditions or other environmental factors that make reliable triggering non-trivial.

Blast Radius

  • A successful attacker escapes the Chrome sandbox and gains code execution in the context of the host process, reading files and secrets accessible to the browser's OS-level user.
  • The attacker can write or modify files on the host, including credential stores, configuration files, or application data outside the browser sandbox.
  • The attacker can crash or destabilize host-level processes, causing service disruption beyond the browser tab boundary.
  • Because scope is changed (S:C in the CVSS vector), impact extends beyond the sandboxed component to other resources on the same host or container.

How HarborGuard Handles This

Available on HarborGuard: detection fires within minutes of ingestion for any image containing a Chrome version below 148.0.7778.216, covering both registry scans and pipeline builds. Where compliance policy permits auto-remediation, HarborGuard rebuilds the image at the patched version, executes a regression run, and opens a PR against affected workloads; for high-severity issues, the median time from CVE publication to merged patch PR is around 90 minutes in environments with auto-remediation enabled. Customers who manage their own patch schedule will see the finding surfaced in their HarborGuard dashboard with CVSS 8.3 scoring and environment-specific routing so the right team can act promptly.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H