CVE-2026-9995: Use after free in WebXR in Google Chrome prior to 148
Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
A use-after-free vulnerability exists in the WebXR component of Google Chrome prior to version 148.0.7778.216. The flaw is reachable over the network without any authentication, but requires a user to visit or be redirected to a crafted HTML page. Successful exploitation gives an attacker arbitrary code execution inside the Chrome sandbox. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for affected environments.
HarborGuard Coverage
Detection of CVE-2026-9995 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of publication from upstream feeds, including custom-built images that bundle Chrome or Chromium. Any image in a customer registry or CI pipeline running a Chrome version below 148.0.7778.216 is flagged automatically.
AvailableHarborGuard scores this CVE at 8.8 HIGH using the CVSS v3.1 vector and weights it further against each customer environment's compliance policy, so findings are routed to the appropriate team inbox without manual filtering. Per-environment context, such as whether the affected image is in a production-facing workload, is surfaced alongside the finding to accelerate prioritization.
AvailableA patched-image rebuild at Chrome 148.0.7778.216 becomes available on HarborGuard as soon as the upstream fix is confirmed. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite against the new image, and opens a PR against any affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker must deliver the crafted HTML page over the network, meaning the target Chrome instance must be reachable in a browsing context exposed to attacker-controlled content (AV:N).
- AuthenticationNot required
No account or credentials are needed; the attacker only needs to get the target to load a page (PR:N).
- Victim interactionRequired
The target user must visit or be directed to the attacker's crafted HTML page, making this a social-engineering or drive-by scenario (UI:R).
- Attack complexityDetail
Exploitation is reliable and imposes no special environmental conditions or race-condition requirements on the attacker (AC:L).
Blast Radius
- The attacker executes arbitrary code within the Chrome renderer sandbox, gaining full control over the compromised browser process.
- Confidential data accessible to the browser process, including stored credentials, session tokens, and page content, is exposed to the attacker.
- The attacker can write or modify data within the sandbox, including cached files and browser state.
- The affected browser process can be crashed or forced into an unrecoverable state, disrupting the user's session.
How HarborGuard Handles This
Available on HarborGuard: detection for CVE-2026-9995 is active across all connected registries and pipelines, matching any image that ships Chrome below 148.0.7778.216. Given the HIGH severity (CVSS 8.8) and the no-authentication, network-reachable attack surface, this CVE is prioritized at the top of the triage queue in environments where compliance policy weights browser-component vulnerabilities at or above their base CVSS score. For customers who opt into auto-remediation, HarborGuard queues a rebuild at Chrome 148.0.7778.216, runs regression tests against the rebuilt image, and opens a patch PR against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuild artifact is staged and the PR is held open pending review.
Metrics
- CVSS v3.1
- 8.8
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H