HarborGuard / CVE
Back to search
HIGHCVE-2026-9992Published Modified CNA Chrome

CVE-2026-9992: Use after free in Network in Google Chrome prior to 148

Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability in the Network component of Google Chrome prior to version 148.0.7778.216 allows a remote attacker to execute arbitrary code inside the Chrome sandbox. The flaw is reachable over the network without any authentication, but requires the victim to visit a crafted HTML page. Successful exploitation gives the attacker arbitrary code execution within the browser sandbox, which can be chained with a sandbox escape for deeper system access. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Chrome or Chromium as a dependency. Any image carrying a Chrome version below 148.0.7778.216 is flagged immediately on match.

Available
Triage

HarborGuard surfaces this CVE with its CVSS v3.1 score of 8.8 (HIGH) and weights it against each customer environment's compliance policy to determine ticket severity and routing. The resulting finding is delivered to the appropriate team inbox within the customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild pinned to Chrome 148.0.7778.216 becomes available in HarborGuard as soon as the upstream package is resolvable. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the exploit over the network; the victim's browser must be able to reach an attacker-controlled or compromised web server.

  • AuthenticationNot required

    No account or credential is needed; the attacker only needs to get the victim to load a crafted page.

  • Victim interactionRequired

    The victim must navigate to or be redirected to the malicious HTML page, making this a social-engineering or drive-by delivery scenario.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other hard-to-control environmental factors.

Blast Radius

  • The attacker gains arbitrary code execution within the Chrome renderer sandbox, enabling them to run attacker-supplied instructions inside the browser process.
  • With sandbox-level code execution established, the attacker can read browser memory, including cached credentials, session tokens, and form-autofill data.
  • Integrity of browser state is fully compromised: the attacker can modify in-memory page content, intercept requests, and inject data into the browser's network layer.
  • A successful sandbox escape chained onto this vulnerability would extend access to the host operating system, affecting availability of the host service.

How HarborGuard Handles This

Available on HarborGuard: any image that packages Chrome or Chromium below version 148.0.7778.216 is detected and flagged as HIGH severity within minutes of the CVE entering upstream feeds. Where compliance policy permits auto-remediation, HarborGuard rebuilds the affected image at version 148.0.7778.216, runs a regression test suite, and opens a pull request against affected workloads; for high-severity issues, the median time from CVE publication to merged patch PR in auto-remediation-enabled environments is around 90 minutes. For environments where auto-remediation is not enabled, the flagged finding is routed to the configured owner inbox so the team can act manually. Until a rebuild is deployed, compensating controls such as network-policy rules that restrict outbound connections to untrusted origins, browser usage policies limiting access to unknown external sites, and egress filtering at the container level can reduce exposure.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H