CVE-2026-9997: Use after free in Input in Google Chrome prior to 148
Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
HarborGuard Analysis
HarborGuard analysisSynopsis
A use-after-free vulnerability in the Input component of Google Chrome (versions prior to 148.0.7778.216) allows a remote attacker who has already compromised the renderer process to escape Chrome's sandbox by delivering a crafted HTML page. The attack requires the victim to interact with the page and benefits from the renderer already being under attacker control, but no authentication is needed. Successful exploitation grants the attacker code execution outside the browser sandbox, enabling full compromise of the host process. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.
HarborGuard Coverage
Detection of CVE-2026-9997 is available across every HarborGuard environment; the CVE is ingested from upstream feeds (NVD, Chrome security advisories, and OSV) within minutes of publication and matched against all customer images, including custom-built images that bundle a Chromium or Chrome binary.
AvailableHarborGuard scores this CVE at 8.3 HIGH per the CVSS v3.1 vector and weights that score against each customer environment's compliance policy before routing findings to the appropriate team inbox within that organization.
AvailableA patched-image rebuild at Chrome 148.0.7778.216 becomes available on HarborGuard for any image found to include an affected Chrome or Chromium version. For customers who opt into auto-remediation, HarborGuard runs the rebuild, executes a regression test pass, and opens a pull request against affected workloads automatically.
AvailableExploit Conditions
- Network reachabilityRequired
The attacker delivers the crafted HTML page over the network, so the target service or user must be reachable from the internet or an accessible network segment.
- AuthenticationNot required
No account or credential is required; the attack is initiated by getting the victim to load a malicious page.
- Victim interactionRequired
The victim must navigate to or open the attacker-controlled HTML page, making this a social-engineering step the attacker must accomplish.
- Attack complexityDetail
Exploitation is rated High complexity because it requires the renderer process to already be compromised before the use-after-free can be leveraged for a sandbox escape, introducing a significant prerequisite condition.
Blast Radius
- An attacker who succeeds reads memory outside the browser sandbox, exposing secrets, credentials, and session data held in other browser processes or the host OS.
- The attacker can write to host-level resources, modifying files, registries, or process memory outside the sandboxed renderer.
- The attacker gains arbitrary code execution in the context of the Chrome browser process on the host, not just inside the sandboxed tab.
- Full sandbox escape means the attacker can crash, persist on, or pivot from the affected host to other systems on the same network.
How HarborGuard Handles This
Available on HarborGuard: any image containing a Chrome or Chromium binary below 148.0.7778.216 is flagged immediately upon CVE ingestion, which typically occurs within minutes of upstream publication. For customers who opt into auto-remediation, HarborGuard rebuilds the image at the patched version, runs a regression test pass, and opens a pull request against affected workloads; for high-severity issues, the median time from CVE publication to merged patch PR in auto-remediation-enabled environments is around 90 minutes. Where compliance policy requires manual sign-off, the finding is routed to the designated team inbox with full CVSS context and the fix version pre-populated. Because this vulnerability requires a pre-compromised renderer as a prerequisite, security teams that cannot immediately patch should also consider network policy controls that restrict outbound connections from Chrome-based workloads, reducing the attacker's ability to exploit a compromised renderer against internal targets.
Metrics
- CVSS v3.1
- 8.3
- Severity
- HIGH
- Fixed in
- 148.0.7778.216
- Affected Products
- 1
Fix available
- Google / Chrome< 148.0.7778.216 (from 148.0.7778.216)
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H