CVE-2026-78911

Google · Chrome

Google Chrome contains an incorrect authorization vulnerability in its USB implementation that could allow a remote attacker to execute arbitrary code outside the sandbox.

Executive summary

A critical authorization vulnerability in Google Chrome allows remote attackers to bypass sandbox protections and execute arbitrary code through social engineering.

Vulnerability

This vulnerability involves incorrect authorization within the USB component of Google Chrome. An unauthenticated remote attacker who has compromised the renderer process can leverage social engineering to escape the sandbox and execute arbitrary code.

Business impact

The vulnerability poses a severe risk to organizational security, as it facilitates a complete sandbox escape and potential remote code execution. Given the CVSS score of 8.3, this flaw represents a High severity risk that could lead to full system compromise, unauthorized data exfiltration, or the installation of persistent malware on user workstations.

Remediation

Immediate Action: Update Google Chrome to version 152.0.7977.65 or later immediately to apply the necessary authorization fixes.

Proactive Monitoring: Monitor endpoint logs for suspicious browser process activity or unauthorized attempts to access USB-related device interfaces.

Compensating Controls: Ensure that users are operating with the principle of least privilege to limit the impact of potential code execution, and utilize endpoint detection and response tools to identify anomalous sandbox-breaking behavior.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The potential for sandbox escape in a widely used browser like Chrome necessitates immediate action. Security teams should prioritize the deployment of the 152.0.7977.65 update across all managed assets to close this authorization gap. Failure to patch allows attackers a pathway to escalate privileges from a compromised renderer process, which could result in significant organizational impact.

More Google CVEs

Sources