CVE-2026-78901
Google · Chrome
A race condition in the V8 engine of Google Chrome allows a remote attacker to achieve arbitrary code execution within the browser sandbox via a crafted HTML page.
Executive summary
A critical race condition vulnerability in the Google Chrome V8 engine exposes users to potential arbitrary code execution when visiting malicious websites.
Vulnerability
The vulnerability is a race condition (CWE-362) located within the V8 JavaScript engine. An unauthenticated remote attacker can trigger this flaw by enticing a user to navigate to a specifically crafted HTML page, potentially leading to code execution inside the sandbox.
Business impact
The ability for an attacker to execute arbitrary code within the browser sandbox poses a significant risk to data confidentiality and integrity. If successfully exploited, this could lead to the theft of sensitive session data, credentials, or the installation of malicious software on the endpoint. With a CVSS score of 7.5, this high severity vulnerability necessitates immediate attention to prevent potential compromise of corporate workstations.
Remediation
Immediate Action: Update Google Chrome to version 152.0.7977.65 or later to apply the necessary security patches.
Proactive Monitoring: Security teams should monitor endpoint security logs for anomalous browser behavior or unexpected process execution patterns originating from the Chrome application.
Compensating Controls: Ensure that browser-based security policies, such as site isolation and advanced threat protection features, are enabled to limit the potential impact of sandbox escapes or local code execution.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the inherent risks associated with browser-based code execution vulnerabilities, it is imperative that all organizations prioritize the deployment of the latest Google Chrome update. Failure to update leaves endpoints exposed to potential exploitation through standard web browsing activities. Please ensure that this update is pushed to all managed devices immediately to maintain a robust security posture.