CVE-2026-9993: Use after free in Views in Google Chrome prior to 148
Use after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted PDF file. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
A use-after-free vulnerability in the Views component of Google Chrome allows a remote attacker who has already compromised the Chrome renderer process to escape the browser sandbox via a crafted PDF file. The attack is reachable over the network but requires the victim to interact with a malicious file, and the CVSS score is 8.3 (High). Successful exploitation gives the attacker full read, write, and execution capability outside the Chrome sandbox, on the host system. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection of CVE-2026-9993 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against all customer images in connected registries and CI/CD pipelines, including custom-built images that bundle a Chromium or Chrome binary.
AvailableHarborGuard is capable of scoring this CVE at 8.3 High using the published CVSS v3.1 vector, with per-environment compliance policy weighting applied on top to adjust priority; findings are routed to the appropriate team inbox within each customer organization based on configured ownership rules.
AvailableA patched-image rebuild at Chrome 148.0.7778.216 is available on HarborGuard for any environment where an affected image is detected. For customers who opt into auto-remediation, HarborGuard performs the rebuild, runs a regression test suite, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the crafted PDF over the network, so the targeted Chrome instance must be reachable or the user must browse to an attacker-controlled resource.
- AuthenticationNot required
No account or credentials are needed; the attacker only needs to get the victim to open a crafted PDF.
- Victim interactionRequired
The victim must open or preview a crafted PDF file, making this a social-engineering-dependent exploit.
- Attack complexityDetail
Attack complexity is High, meaning the attacker must have already compromised the Chrome renderer process before this use-after-free can be leveraged for sandbox escape.
Blast Radius
- Attacker gains code execution outside the Chrome sandbox, breaking the primary security boundary between web content and the host OS.
- Confidential data accessible to the browser process, including stored credentials, cookies, and session tokens, becomes readable by the attacker.
- The attacker can write to the filesystem and modify files accessible under the user account running Chrome.
- The attacker can crash or terminate host processes, disrupting any service running under the same user context.
How HarborGuard Handles This
Available on HarborGuard: images containing Google Chrome prior to 148.0.7778.216 are flagged automatically as soon as the CVE is ingested. A rebuilt image at the fixed version is available for any affected image detected in a customer registry or pipeline. For customers who opt into auto-remediation, HarborGuard triggers the rebuild, runs regression tests, and opens a pull request against affected workloads; for high-severity issues, the median time from CVE publication to merged patch PR in auto-remediation environments is around 90 minutes. Where compliance policy requires manual approval, the rebuilt image is staged and the finding is routed to the designated security or platform team inbox for review. Customers who bundle Chromium in custom base images are also covered, provided those images are scanned through HarborGuard pipelines.
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H