CVE-2026-9952: Use after free in WebAudio in Google Chrome prior to 148
Use after free in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
Use-after-free in the WebAudio component of Google Chrome (versions prior to 148.0.7778.216) allows a remote attacker to execute arbitrary code inside the Chrome sandbox by luring a user to a crafted HTML page. The vulnerability is reachable over the network and requires no authentication, though the victim must visit an attacker-controlled page. Successful exploitation gives the attacker code execution within the browser sandbox. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection is available across every HarborGuard environment - CVE-2026-9952 is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle a Chrome or Chromium binary. Coverage extends to any image layer where an affected Chrome version is present.
AvailableHarborGuard scores this finding at CVSS 8.8 (HIGH) and weights it against each environment's compliance policy to determine urgency and ownership. Triage routing is available to deliver the finding to the appropriate team inbox within each customer organization.
AvailableA patched-image rebuild pinned to Chrome 148.0.7778.216 becomes available on HarborGuard for any image found to carry an affected version. For customers with auto-remediation enabled, HarborGuard performs the rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network by hosting a crafted HTML page that the victim's browser fetches remotely.
- AuthenticationNot required
No account or credential is needed on any system; the attacker only needs to get the victim to load a page.
- Victim interactionRequired
The victim must navigate to or be redirected to an attacker-controlled HTML page, making this a social-engineering or malvertising vector.
- Attack complexityDetail
Exploit complexity is low - no race conditions, memory-layout dependencies, or special environmental conditions are required for reliable exploitation.
Blast Radius
- Attacker executes arbitrary code inside the Chrome renderer sandbox, gaining full control of the sandboxed process.
- Confidential data accessible to the browser context, including stored session tokens, page contents, and in-memory credentials, is readable by the attacker.
- The attacker can write or modify data within the sandboxed process, including manipulating in-page state and any data the renderer can reach.
- The affected browser process can be crashed or destabilized, disrupting service for the user session.
How HarborGuard Handles This
Available on HarborGuard: any image carrying a Chrome binary older than 148.0.7778.216 is flagged automatically when the CVE enters the ingest pipeline. For customers with auto-remediation enabled, HarborGuard rebuilds the image at the patched version, runs regression tests, and opens a pull request against affected workloads - median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. For customers who manage patching manually, the finding is routed to the configured team inbox with the CVSS 8.8 score, affected image list, and fix version clearly noted. Because this vulnerability requires victim interaction via a browser, customers who cannot immediately rebuild are advised to apply network-policy controls that restrict access to untrusted external origins and to review browser deployment patterns within their container workloads.
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H