HarborGuard / CVE
Back to search
HIGHCVE-2026-9984Published Modified CNA Chrome

CVE-2026-9984: Use after free in UI in Google Chrome on Windows prior to 148

Use after free in UI in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability in the UI component of Google Chrome on Windows allows a remote attacker to execute arbitrary code. The flaw is reachable over the network without any authentication, but requires the victim to visit a crafted HTML page. Successful exploitation gives the attacker full code execution in the context of the browser process, enabling data theft, system tampering, or further compromise. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-9984 is available across every HarborGuard environment, with CVE feed ingestion typically completing within minutes of publication and immediate matching against images in customer registries and CI/CD pipelines. Coverage extends to custom-built images that bundle Chrome or Chromium on Windows base layers.

Available
Triage

HarborGuard is capable of scoring this CVE at 8.8 HIGH using the recorded CVSS v3.1 vector, and can weight that score against each environment's compliance policy to determine urgency. Findings are routed to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild at Chrome version 148.0.7778.216 becomes available on HarborGuard once the upstream package is resolvable in the relevant base image. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network; the target Chrome instance must be able to reach and render an attacker-controlled HTML page.

  • AuthenticationNot required

    No account, credential, or prior authentication is needed on the target system to trigger the vulnerability.

  • Victim interactionRequired

    The victim must open or be redirected to a crafted HTML page, making this a social-engineering vector (for example, a phishing link or a malicious ad).

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other unpredictable environmental factors.

Blast Radius

  • Attacker executes arbitrary code in the browser process, gaining the ability to read files, session tokens, saved passwords, and other data accessible to the browser.
  • Attacker can write or modify files and registry entries within the permissions of the browser process user.
  • Attacker can crash or hang the browser, denying service to the affected user.
  • With code execution established, the attacker can pivot to further compromise the underlying Windows host depending on sandbox escape opportunities.

How HarborGuard Handles This

Available on HarborGuard: detection for this CVE is active across all connected registries and pipelines, matching any image that bundles an affected Chrome version below 148.0.7778.216. For customers who opt into auto-remediation, HarborGuard can trigger a rebuild at the fixed version, run regression tests against the new image, and open a pull request against affected workloads; for high-severity CVEs the median time from publication to merged patch PR in auto-remediation-enabled environments is around 90 minutes. Where compliance policy requires manual review, the finding is surfaced in the dashboard with the CVSS 8.8 HIGH score and full vector detail for prioritization. Customers without auto-remediation should treat this as a high-urgency manual update given the combination of no-authentication-required, network-reachable delivery, and full code execution impact.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H