HarborGuard / CVE
Back to search
HIGHCVE-2026-9963Published Modified CNA Chrome

CVE-2026-9963: Uninitialized Use in iOS in Google Chrome on iOS prior to 148

Uninitialized Use in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

Uninitialized memory use in Google Chrome on iOS (versions prior to 148.0.7778.216) allows a remote attacker to execute arbitrary code inside the browser sandbox. The attacker must reach the victim over the network and convince them to perform specific UI gestures on a crafted HTML page; no credentials are required. Successful exploitation gives the attacker code execution within the Chrome sandbox, with high impact to confidentiality, integrity, and availability. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection for CVE-2026-9963 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built iOS app container images. Coverage extends to any image layering a Chrome on iOS dependency at a version below 148.0.7778.216.

Available
Triage

HarborGuard scores this CVE at 7.5 HIGH (CVSS v3.1) and can weight that score against each customer environment's compliance policy to adjust priority accordingly. Triage findings are routed to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild pinned to Chrome 148.0.7778.216 becomes available on HarborGuard for any environment where an affected image is detected. For customers with auto-remediation enabled, HarborGuard triggers a rebuild, runs a regression test suite against the updated image, and opens a pull request against affected workloads.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the victim's device over the network, delivering a crafted HTML page from a remote origin.

  • AuthenticationNot required

    No account or credential is needed; the attacker only needs the victim to visit a malicious page.

  • Victim interactionRequired

    The victim must be socially engineered into performing specific UI gestures on the crafted page, making phishing or deceptive UI a necessary part of the attack chain.

  • Attack complexityDetail

    Attack complexity is high, meaning the attacker must account for timing, specific gesture sequences, or other environmental conditions that cannot be fully controlled, reducing exploit reliability.

Blast Radius

  • Attacker achieves arbitrary code execution within the Chrome sandbox on the victim's iOS device.
  • Confidentiality impact is high: sandbox-accessible data such as browsing history, cached credentials, and session tokens can be read.
  • Integrity impact is high: the attacker can modify data and state within the sandbox, including stored site data and local app storage accessible to Chrome.
  • Availability impact is high: the attacker can crash or destabilize the Chrome process, disrupting browser availability on the device.

How HarborGuard Handles This

Available on HarborGuard: detection for this CVE fires within minutes of ingestion and surfaces any image carrying a vulnerable Chrome on iOS version below 148.0.7778.216. For customers with auto-remediation enabled, HarborGuard makes a rebuilt image at the patched version available, runs regression tests, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuild is queued and the owning team is notified with full CVSS context and affected image inventory. Because this vulnerability requires victim interaction via crafted UI gestures, network-policy controls that restrict which origins users can reach from managed environments serve as a useful compensating control until the patched image is deployed.

See how HarborGuard automates this

Metrics

CVSS v3.1
7.5
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H