CVE-2026-9992: Use after free in Network in Google Chrome prior to 148
Use after free in Network in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
A use-after-free vulnerability in the Network component of Google Chrome prior to version 148.0.7778.216 allows a remote attacker to execute arbitrary code inside the Chrome sandbox. The flaw is reachable over the network without any authentication, but requires the victim to visit a crafted HTML page. Successful exploitation gives the attacker arbitrary code execution within the browser sandbox, which can be chained with a sandbox escape for deeper system access. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images, including custom-built images that bundle Chrome or Chromium as a dependency. Any image carrying a Chrome version below 148.0.7778.216 is flagged immediately on match.
AvailableHarborGuard surfaces this CVE with its CVSS v3.1 score of 8.8 (HIGH) and weights it against each customer environment's compliance policy to determine ticket severity and routing. The resulting finding is delivered to the appropriate team inbox within the customer organization based on configured ownership rules.
AvailableA patched-image rebuild pinned to Chrome 148.0.7778.216 becomes available in HarborGuard as soon as the upstream package is resolvable. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite against the new image, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the exploit over the network; the victim's browser must be able to reach an attacker-controlled or compromised web server.
- AuthenticationNot required
No account or credential is needed; the attacker only needs to get the victim to load a crafted page.
- Victim interactionRequired
The victim must navigate to or be redirected to the malicious HTML page, making this a social-engineering or drive-by delivery scenario.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and does not depend on race conditions, specific memory layouts, or other hard-to-control environmental factors.
Blast Radius
- The attacker gains arbitrary code execution within the Chrome renderer sandbox, enabling them to run attacker-supplied instructions inside the browser process.
- With sandbox-level code execution established, the attacker can read browser memory, including cached credentials, session tokens, and form-autofill data.
- Integrity of browser state is fully compromised: the attacker can modify in-memory page content, intercept requests, and inject data into the browser's network layer.
- A successful sandbox escape chained onto this vulnerability would extend access to the host operating system, affecting availability of the host service.
How HarborGuard Handles This
Available on HarborGuard: any image that packages Chrome or Chromium below version 148.0.7778.216 is detected and flagged as HIGH severity within minutes of the CVE entering upstream feeds. Where compliance policy permits auto-remediation, HarborGuard rebuilds the affected image at version 148.0.7778.216, runs a regression test suite, and opens a pull request against affected workloads; for high-severity issues, the median time from CVE publication to merged patch PR in auto-remediation-enabled environments is around 90 minutes. For environments where auto-remediation is not enabled, the flagged finding is routed to the configured owner inbox so the team can act manually. Until a rebuild is deployed, compensating controls such as network-policy rules that restrict outbound connections to untrusted origins, browser usage policies limiting access to unknown external sites, and egress filtering at the container level can reduce exposure.
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H