CVE-2026-78900
Google · Chrome
A critical flaw in Google Chrome Media components allows unauthenticated remote attackers to execute arbitrary code outside the browser sandbox via a crafted HTML page.
Executive summary
Google Chrome versions prior to 152.0.7977.65 are vulnerable to a remote code execution flaw that poses a critical risk to system integrity.
Vulnerability
This vulnerability is caused by improper input validation within the Media component of the browser. An unauthenticated remote attacker can trigger this flaw by enticing a user to visit a malicious website, potentially leading to arbitrary code execution outside the sandbox environment.
Business impact
The ability for an attacker to execute arbitrary code outside the browser sandbox represents a total compromise of the affected host system. Given the high CVSS score of 9.6, this vulnerability is categorized as critical, as it bypasses standard browser security boundaries and could lead to full system takeover, data exfiltration, or the deployment of persistent malware within the corporate network.
Remediation
Immediate Action: Update Google Chrome to version 152.0.7977.65 or later immediately across all managed endpoints to apply the necessary security patches.
Proactive Monitoring: Monitor network traffic for unusual outbound connections from browser processes and review endpoint security logs for signs of unauthorized process creation or unexpected shell execution.
Compensating Controls: Ensure that all users are operating with the least privilege necessary, and consider deploying browser isolation technologies to mitigate the risk of successful sandbox escapes.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the critical nature of this vulnerability and the potential for complete system compromise, organizations should prioritize the deployment of the Chrome update. Administrators must ensure that all instances of Chrome are updated to the patched version as soon as possible to mitigate the risk of remote code execution attacks.