HarborGuard / CVE
Back to search
HIGHCVE-2026-9952Published Modified CNA Chrome

CVE-2026-9952: Use after free in WebAudio in Google Chrome prior to 148

Use after free in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

Use-after-free in the WebAudio component of Google Chrome (versions prior to 148.0.7778.216) allows a remote attacker to execute arbitrary code inside the Chrome sandbox by luring a user to a crafted HTML page. The vulnerability is reachable over the network and requires no authentication, though the victim must visit an attacker-controlled page. Successful exploitation gives the attacker code execution within the browser sandbox. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment - CVE-2026-9952 is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle a Chrome or Chromium binary. Coverage extends to any image layer where an affected Chrome version is present.

Available
Triage

HarborGuard scores this finding at CVSS 8.8 (HIGH) and weights it against each environment's compliance policy to determine urgency and ownership. Triage routing is available to deliver the finding to the appropriate team inbox within each customer organization.

Available
Patch

A patched-image rebuild pinned to Chrome 148.0.7778.216 becomes available on HarborGuard for any image found to carry an affected version. For customers with auto-remediation enabled, HarborGuard performs the rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by hosting a crafted HTML page that the victim's browser fetches remotely.

  • AuthenticationNot required

    No account or credential is needed on any system; the attacker only needs to get the victim to load a page.

  • Victim interactionRequired

    The victim must navigate to or be redirected to an attacker-controlled HTML page, making this a social-engineering or malvertising vector.

  • Attack complexityDetail

    Exploit complexity is low - no race conditions, memory-layout dependencies, or special environmental conditions are required for reliable exploitation.

Blast Radius

  • Attacker executes arbitrary code inside the Chrome renderer sandbox, gaining full control of the sandboxed process.
  • Confidential data accessible to the browser context, including stored session tokens, page contents, and in-memory credentials, is readable by the attacker.
  • The attacker can write or modify data within the sandboxed process, including manipulating in-page state and any data the renderer can reach.
  • The affected browser process can be crashed or destabilized, disrupting service for the user session.

How HarborGuard Handles This

Available on HarborGuard: any image carrying a Chrome binary older than 148.0.7778.216 is flagged automatically when the CVE enters the ingest pipeline. For customers with auto-remediation enabled, HarborGuard rebuilds the image at the patched version, runs regression tests, and opens a pull request against affected workloads - median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. For customers who manage patching manually, the finding is routed to the configured team inbox with the CVSS 8.8 score, affected image list, and fix version clearly noted. Because this vulnerability requires victim interaction via a browser, customers who cannot immediately rebuild are advised to apply network-policy controls that restrict access to untrusted external origins and to review browser deployment patterns within their container workloads.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H