CVE-2026-78900

Google · Chrome

A critical flaw in Google Chrome Media components allows unauthenticated remote attackers to execute arbitrary code outside the browser sandbox via a crafted HTML page.

Executive summary

Google Chrome versions prior to 152.0.7977.65 are vulnerable to a remote code execution flaw that poses a critical risk to system integrity.

Vulnerability

This vulnerability is caused by improper input validation within the Media component of the browser. An unauthenticated remote attacker can trigger this flaw by enticing a user to visit a malicious website, potentially leading to arbitrary code execution outside the sandbox environment.

Business impact

The ability for an attacker to execute arbitrary code outside the browser sandbox represents a total compromise of the affected host system. Given the high CVSS score of 9.6, this vulnerability is categorized as critical, as it bypasses standard browser security boundaries and could lead to full system takeover, data exfiltration, or the deployment of persistent malware within the corporate network.

Remediation

Immediate Action: Update Google Chrome to version 152.0.7977.65 or later immediately across all managed endpoints to apply the necessary security patches.

Proactive Monitoring: Monitor network traffic for unusual outbound connections from browser processes and review endpoint security logs for signs of unauthorized process creation or unexpected shell execution.

Compensating Controls: Ensure that all users are operating with the least privilege necessary, and consider deploying browser isolation technologies to mitigate the risk of successful sandbox escapes.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the critical nature of this vulnerability and the potential for complete system compromise, organizations should prioritize the deployment of the Chrome update. Administrators must ensure that all instances of Chrome are updated to the patched version as soon as possible to mitigate the risk of remote code execution attacks.

More Google CVEs

Sources