HarborGuard / CVE
Back to search
HIGHCVE-2026-9995Published Modified CNA Chrome

CVE-2026-9995: Use after free in WebXR in Google Chrome prior to 148

Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability exists in the WebXR component of Google Chrome prior to version 148.0.7778.216. The flaw is reachable over the network without any authentication, but requires a user to visit or be redirected to a crafted HTML page. Successful exploitation gives an attacker arbitrary code execution inside the Chrome sandbox. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for affected environments.

HarborGuard Coverage

Detection

Detection of CVE-2026-9995 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of publication from upstream feeds, including custom-built images that bundle Chrome or Chromium. Any image in a customer registry or CI pipeline running a Chrome version below 148.0.7778.216 is flagged automatically.

Available
Triage

HarborGuard scores this CVE at 8.8 HIGH using the CVSS v3.1 vector and weights it further against each customer environment's compliance policy, so findings are routed to the appropriate team inbox without manual filtering. Per-environment context, such as whether the affected image is in a production-facing workload, is surfaced alongside the finding to accelerate prioritization.

Available
Patch

A patched-image rebuild at Chrome 148.0.7778.216 becomes available on HarborGuard as soon as the upstream fix is confirmed. For customers who opt into auto-remediation, HarborGuard triggers a rebuild, runs a regression test suite against the new image, and opens a PR against any affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker must deliver the crafted HTML page over the network, meaning the target Chrome instance must be reachable in a browsing context exposed to attacker-controlled content (AV:N).

  • AuthenticationNot required

    No account or credentials are needed; the attacker only needs to get the target to load a page (PR:N).

  • Victim interactionRequired

    The target user must visit or be directed to the attacker's crafted HTML page, making this a social-engineering or drive-by scenario (UI:R).

  • Attack complexityDetail

    Exploitation is reliable and imposes no special environmental conditions or race-condition requirements on the attacker (AC:L).

Blast Radius

  • The attacker executes arbitrary code within the Chrome renderer sandbox, gaining full control over the compromised browser process.
  • Confidential data accessible to the browser process, including stored credentials, session tokens, and page content, is exposed to the attacker.
  • The attacker can write or modify data within the sandbox, including cached files and browser state.
  • The affected browser process can be crashed or forced into an unrecoverable state, disrupting the user's session.

How HarborGuard Handles This

Available on HarborGuard: detection for CVE-2026-9995 is active across all connected registries and pipelines, matching any image that ships Chrome below 148.0.7778.216. Given the HIGH severity (CVSS 8.8) and the no-authentication, network-reachable attack surface, this CVE is prioritized at the top of the triage queue in environments where compliance policy weights browser-component vulnerabilities at or above their base CVSS score. For customers who opt into auto-remediation, HarborGuard queues a rebuild at Chrome 148.0.7778.216, runs regression tests against the rebuilt image, and opens a patch PR against affected workloads; median time from CVE publication to merged patch PR for high-severity issues is around 90 minutes in environments with auto-remediation enabled. Where compliance policy requires manual approval, the rebuild artifact is staged and the PR is held open pending review.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.8
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H