HarborGuard / CVE
Back to search
HIGHCVE-2026-9982Published Modified CNA Chrome

CVE-2026-9982: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148

Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

Insufficient input validation in the ANGLE graphics layer of Google Chrome (versions prior to 148.0.7778.216) allows a remote attacker who has already compromised the Chrome renderer process to escape the browser sandbox. The exploit is reachable over the network but requires the victim to visit a crafted HTML page, and the attacker must already control the renderer, making this a chained attack. Successful exploitation gives the attacker full code execution outside the Chrome sandbox, with high impact on confidentiality, integrity, and availability. A patched-image rebuild at 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection for CVE-2026-9982 is available across every HarborGuard environment; the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in registries and CI/CD pipelines, including custom-built images that bundle Chrome or Chromium.

Available
Triage

HarborGuard is capable of scoring this CVE at CVSS 8.3 (HIGH) and weighting it further against each environment's compliance policy, then routing the finding to the appropriate team inbox within the customer organization.

Available
Patch

A patched-image rebuild at Chrome 148.0.7778.216 is available on HarborGuard for any image found to carry an affected version. For customers who opt into auto-remediation, HarborGuard can perform the rebuild, run a regression test suite, and open a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network; the target must be reachable via a browser that loads the crafted HTML page from a remote origin.

  • AuthenticationNot required

    No account or credential is needed; the attacker simply serves a malicious page to any Chrome user running a vulnerable version.

  • Victim interactionRequired

    The victim must visit the attacker-controlled HTML page in Chrome, making social engineering or a malicious ad/link a required step in the attack chain.

  • Attack complexityDetail

    Attack complexity is High because the attacker must first have compromised the Chrome renderer process as a prerequisite before this vulnerability can be used to escape the sandbox.

Blast Radius

  • Attacker breaks out of the Chrome browser sandbox, gaining arbitrary code execution at the privilege level of the Chrome process on the host OS.
  • Files, credentials, and secrets accessible to the OS user running Chrome can be read directly.
  • The attacker can write or modify files on the host, enabling persistence mechanisms such as dropped binaries or modified startup entries.
  • The host process can be terminated or destabilized, causing a full browser or system crash.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-9982 is matched against all images in connected registries and pipelines immediately after ingestion. For environments where images bundle Chrome or Chromium, a patched rebuild at version 148.0.7778.216 is available as soon as HarborGuard identifies an affected layer. For customers who opt into auto-remediation, the typical flow is a rebuilt image, an automated regression run, and a PR opened against affected workloads; for HIGH-severity issues, the median time from CVE publication to merged patch PR in auto-remediation-enabled environments is around 90 minutes. For environments where auto-remediation is not permitted by compliance policy, HarborGuard surfaces the finding with CVSS 8.3 scoring and recommended remediation steps, and teams can trigger a manual rebuild from the finding detail page. As an interim compensating control, network policy rules that restrict which container workloads can spawn or embed a browser process reduce the attack surface while a patched image is being promoted through the pipeline.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H