HarborGuard / CVE
Back to search
HIGHCVE-2026-9994Published Modified CNA Chrome

CVE-2026-9994: Use after free in Core in Google Chrome on Windows prior to 148

Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability in the Core component of Google Chrome on Windows (versions before 148.0.7778.216) allows a remote attacker who has already compromised the renderer process to escape Chrome's sandbox by delivering a crafted HTML page. The exploit requires the victim to interact with attacker-controlled content and involves high attack complexity due to the prerequisite renderer compromise. Successful exploitation gives the attacker code execution outside the browser sandbox, effectively breaking the primary isolation boundary between web content and the host OS. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version of Chrome.

HarborGuard Coverage

Detection

Detection of CVE-2026-9994 is available across every HarborGuard environment: the CVE is ingested from upstream feeds within minutes of publication and matched against customer images in connected registries and CI/CD pipelines, including custom-built images that bundle a Chrome or Chromium installation.

Available
Triage

Triage is available with the CVSS v3.1 base score of 8.3 (HIGH) applied automatically; per-environment compliance policy weighting can escalate or adjust priority, and the finding is routed to the appropriate team inbox within each customer organization based on configured ownership rules.

Available
Patch

A patched-image rebuild at Chrome 148.0.7778.216 is available on HarborGuard for any image found to contain an affected version. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs the configured regression test suite, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the crafted HTML page over the network, so the target service or user must be reachable from an external or network-adjacent origin.

  • AuthenticationNot required

    No account or credential is needed; the attacker only needs to get the victim to load the malicious page.

  • Victim interactionRequired

    The victim must navigate to or otherwise load a crafted HTML page, making this a social-engineering or drive-by scenario.

  • Attack complexityDetail

    Attack complexity is rated High because the attacker must first achieve a renderer process compromise before this use-after-free can be leveraged for a sandbox escape.

Blast Radius

  • Reads sensitive data from memory outside the renderer sandbox, including session tokens, credentials, or other in-process secrets.
  • Writes to or modifies host OS resources that the Chrome sandbox would normally block, such as filesystem paths or registry keys.
  • Crashes or destabilizes the Chrome process, causing a denial of service for the affected user session.
  • Achieves arbitrary code execution on the underlying Windows host, fully breaking Chrome sandbox isolation.

How HarborGuard Handles This

Available on HarborGuard: images containing Google Chrome prior to 148.0.7778.216 on Windows are flagged as soon as the CVE is ingested, typically within minutes of publication. A rebuilt image at the patched version is made available for affected environments. For customers who opt into auto-remediation, HarborGuard rebuilds the image, executes the configured regression test suite, and opens a pull request against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual review before remediation, the finding is queued with full CVSS context and policy-weighted priority for team action. Because this vulnerability requires a pre-existing renderer compromise as a prerequisite, customers who cannot immediately update may consider network-policy controls that restrict which origins can deliver HTML content to browser instances embedded in containerized workloads, reducing the attacker's ability to reach the renderer in the first place.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H