HarborGuard / CVE
Back to search
HIGHCVE-2026-9993Published Modified CNA Chrome

CVE-2026-9993: Use after free in Views in Google Chrome prior to 148

Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability in the Views component of Google Chrome allows a remote attacker who has already compromised the Chrome renderer process to escape the browser sandbox via a crafted PDF file. The attack is reachable over the network but requires the victim to interact with a malicious file, and the CVSS score is 8.3 (High). Successful exploitation gives the attacker full read, write, and execution capability outside the Chrome sandbox, on the host system. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-9993 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that bundle a Chromium or Chrome binary.

Available
Triage

HarborGuard is capable of scoring this CVE at 8.3 High using the published CVSS v3.1 vector, with per-environment compliance policy weighting applied on top to adjust priority; findings are routed to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild at Chrome 148.0.7778.216 is available on HarborGuard for any environment where an affected image is detected. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the crafted PDF over the network, so the targeted Chrome instance must be reachable or the user must browse to an attacker-controlled resource.

  • AuthenticationNot required

    No account or credentials are needed; the attacker only needs to get the victim to open a crafted PDF.

  • Victim interactionRequired

    The victim must open or preview a crafted PDF file, making this a social-engineering-dependent exploit.

  • Attack complexityDetail

    Attack complexity is High, meaning the attacker must have already compromised the Chrome renderer process before this use-after-free can be leveraged for sandbox escape.

Blast Radius

  • Attacker gains code execution outside the Chrome sandbox, breaking the primary security boundary between web content and the host OS.
  • Confidential data accessible to the browser process, including stored credentials, cookies, and session tokens, becomes readable by the attacker.
  • The attacker can write to the filesystem and modify files accessible under the user account running Chrome.
  • The attacker can crash or terminate host processes, disrupting any service running under the same user context.

How HarborGuard Handles This

Available on HarborGuard: images containing Google Chrome prior to 148.0.7778.216 are flagged automatically as soon as the CVE is ingested. A rebuilt image at the fixed version is available for any affected image detected in a customer registry or pipeline. For customers who opt into auto-remediation, HarborGuard triggers the rebuild, runs regression tests, and opens a pull request against affected workloads; for high-severity issues, the median time from CVE publication to merged patch PR in auto-remediation environments is around 90 minutes. Where compliance policy requires manual approval, the rebuilt image is staged and the finding is routed to the designated security or platform team inbox for review. Customers who bundle Chromium in custom base images are also covered, provided those images are scanned through HarborGuard pipelines.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H