CVE-2026-78891
8.8Google · Chrome
A buffer overflow vulnerability exists in the WebRTC component of Google Chrome, allowing remote attackers to execute arbitrary code via a crafted HTML page.
Executive summary
A critical buffer overflow in Google Chrome allows unauthenticated remote attackers to achieve arbitrary code execution through malicious web content.
Vulnerability
This vulnerability is a buffer overflow (CWE-122) within the WebRTC component. It can be triggered by an unauthenticated remote attacker who lures a user to a crafted HTML page, leading to code execution within the browser sandbox.
Business impact
The ability for a remote attacker to execute arbitrary code within a browser environment poses a significant risk to organizational security. This vulnerability could lead to the theft of session tokens, credential harvesting, or the deployment of malware on end-user workstations. While the CVSS score of 8.8 reflects a high severity, the potential for total system impact necessitates immediate attention to prevent lateral movement within the corporate network.
Remediation
Immediate Action: Update all instances of Google Chrome to version 152.0.7977.65 or later to resolve the underlying buffer overflow.
Proactive Monitoring: Review endpoint security logs for unusual browser activity or unexpected child processes spawned by the Chrome executable.
Compensating Controls: Deploy endpoint protection platforms capable of detecting browser-based exploitation and utilize web filtering solutions to block access to untrusted or malicious domains.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the capability for remote code execution, organizations should prioritize the deployment of the Chrome update across all managed devices. Failure to patch this vulnerability leaves the browser susceptible to exploitation by malicious web pages, which could compromise the integrity and confidentiality of the entire workstation.