HarborGuard / CVE
Back to search
HIGHCVE-2026-9962Published Modified CNA Chrome

CVE-2026-9962: Use after free in WebRTC in Google Chrome prior to 148

Use after free in WebRTC in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability in the WebRTC component of Google Chrome prior to version 148.0.7778.216 allows a remote attacker to execute arbitrary code inside the Chrome sandbox by tricking a user into visiting a crafted HTML page. The vulnerability is reachable over the network, requires no authentication, but does require the victim to load attacker-controlled content. A patched-image rebuild at Chrome 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-9962 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of ingestion from upstream feeds, including custom-built images that bundle a Chromium or Chrome runtime. Any container image carrying a Chrome version below 148.0.7778.216 is flagged automatically as affected images move through customer registries and CI pipelines.

Available
Triage

HarborGuard scores this CVE at CVSS 8.8 (HIGH) and weights it against each customer environment's compliance policy to determine routing priority. Triage results are delivered to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild at Chrome 148.0.7778.216 becomes available on HarborGuard for any environment where an affected image is detected. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network by serving a crafted HTML page, so the victim's browser must be able to reach attacker-controlled web content.

  • AuthenticationNot required

    No account or credential is needed; the attacker only needs to get a user to load the malicious page.

  • Victim interactionRequired

    The victim must visit or be redirected to a crafted HTML page, making this a social-engineering or malicious-ad delivery scenario.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other environmental preconditions.

Blast Radius

  • Executes arbitrary attacker-supplied code inside the Chrome renderer sandbox, giving the attacker control of the renderer process.
  • Reads in-page data including session tokens, form contents, and any secrets accessible to the current browsing context.
  • Modifies in-page state and can initiate network requests from the victim's browser session.
  • Crashes or destabilizes the affected renderer process, disrupting the user's session.

How HarborGuard Handles This

Available on HarborGuard: detection of CVE-2026-9962 is active for any image carrying Chrome below 148.0.7778.216, matched against customer registries and pipelines within minutes of CVE publication. A patched rebuild at 148.0.7778.216 is available for affected images. For customers who opt into auto-remediation, HarborGuard rebuilds the image, runs regression tests, and opens a PR against affected workloads; for HIGH-severity issues the median time from CVE publication to a merged patch PR in auto-remediation-enabled environments is around 90 minutes. Where compliance policy requires manual approval, the rebuilt image and a prioritized alert are staged and waiting for review. Given the sandbox-escape potential of this class of use-after-free bug, upgrading to the fixed version is the only reliable mitigation; there is no safe configuration workaround for the underlying memory-safety defect.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H