HarborGuard / CVE
Back to search
HIGHCVE-2026-9997Published Modified CNA Chrome

CVE-2026-9997: Use after free in Input in Google Chrome prior to 148

Use after free in Input in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

HarborGuard Analysis

HarborGuard analysis

Synopsis

A use-after-free vulnerability in the Input component of Google Chrome (versions prior to 148.0.7778.216) allows a remote attacker who has already compromised the renderer process to escape Chrome's sandbox by delivering a crafted HTML page. The attack requires the victim to interact with the page and benefits from the renderer already being under attacker control, but no authentication is needed. Successful exploitation grants the attacker code execution outside the browser sandbox, enabling full compromise of the host process. A patched-image rebuild at version 148.0.7778.216 is available on HarborGuard for environments running an affected version.

HarborGuard Coverage

Detection

Detection of CVE-2026-9997 is available across every HarborGuard environment; the CVE is ingested from upstream feeds (NVD, Chrome security advisories, and OSV) within minutes of publication and matched against all customer images, including custom-built images that bundle a Chromium or Chrome binary.

Available
Triage

HarborGuard scores this CVE at 8.3 HIGH per the CVSS v3.1 vector and weights that score against each customer environment's compliance policy before routing findings to the appropriate team inbox within that organization.

Available
Patch

A patched-image rebuild at Chrome 148.0.7778.216 becomes available on HarborGuard for any image found to include an affected Chrome or Chromium version. For customers who opt into auto-remediation, HarborGuard runs the rebuild, executes a regression test pass, and opens a pull request against affected workloads automatically.

Available

Exploit Conditions

  • Network reachabilityRequired

    The attacker delivers the crafted HTML page over the network, so the target service or user must be reachable from the internet or an accessible network segment.

  • AuthenticationNot required

    No account or credential is required; the attack is initiated by getting the victim to load a malicious page.

  • Victim interactionRequired

    The victim must navigate to or open the attacker-controlled HTML page, making this a social-engineering step the attacker must accomplish.

  • Attack complexityDetail

    Exploitation is rated High complexity because it requires the renderer process to already be compromised before the use-after-free can be leveraged for a sandbox escape, introducing a significant prerequisite condition.

Blast Radius

  • An attacker who succeeds reads memory outside the browser sandbox, exposing secrets, credentials, and session data held in other browser processes or the host OS.
  • The attacker can write to host-level resources, modifying files, registries, or process memory outside the sandboxed renderer.
  • The attacker gains arbitrary code execution in the context of the Chrome browser process on the host, not just inside the sandboxed tab.
  • Full sandbox escape means the attacker can crash, persist on, or pivot from the affected host to other systems on the same network.

How HarborGuard Handles This

Available on HarborGuard: any image containing a Chrome or Chromium binary below 148.0.7778.216 is flagged immediately upon CVE ingestion, which typically occurs within minutes of upstream publication. For customers who opt into auto-remediation, HarborGuard rebuilds the image at the patched version, runs a regression test pass, and opens a pull request against affected workloads; for high-severity issues, the median time from CVE publication to merged patch PR in auto-remediation-enabled environments is around 90 minutes. Where compliance policy requires manual sign-off, the finding is routed to the designated team inbox with full CVSS context and the fix version pre-populated. Because this vulnerability requires a pre-compromised renderer as a prerequisite, security teams that cannot immediately patch should also consider network policy controls that restrict outbound connections from Chrome-based workloads, reducing the attacker's ability to exploit a compromised renderer against internal targets.

See how HarborGuard automates this

Metrics

CVSS v3.1
8.3
Severity
HIGH
Fixed in
148.0.7778.216
Affected Products
1

Fix available

148.0.7778.216
Affected packages
  • Google / Chrome
    < 148.0.7778.216 (from 148.0.7778.216)
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H