CVE-2026-78915
Google · Chrome
A race condition in the Enterprise component of Google Chrome on Windows allows an adjacent attacker to execute arbitrary code outside the sandbox through crafted network traffic.
Executive summary
A critical race condition vulnerability in Google Chrome for Windows allows adjacent attackers to achieve remote code execution, posing a significant threat to enterprise environments.
Vulnerability
This is a race condition (CWE-362) located within the Enterprise component of the browser. The vulnerability can be triggered by an unauthenticated attacker located on the same network segment (adjacent) through specially crafted network traffic.
Business impact
The ability to execute arbitrary code outside the browser sandbox allows an attacker to compromise the underlying host system, potentially leading to full system takeover and unauthorized access to sensitive corporate data. Although the Chromium project labels the security severity as low, the CVSS score of 7.5 reflects a high severity rating, indicating that the potential for lateral movement and host compromise remains a substantial business risk.
Remediation
Immediate Action: Update all Google Chrome instances on Windows to version 152.0.7977.65 or later immediately.
Proactive Monitoring: Monitor network traffic for unusual patterns or spikes in activity originating from adjacent devices that may indicate attempts to exploit race conditions in enterprise services.
Compensating Controls: Implement network segmentation to limit the number of devices capable of reaching enterprise-managed workstations and ensure that host-based firewalls are configured to block unauthorized traffic.
Exploitation status
Public Exploit Available: False
Analyst recommendation
Given the high CVSS score and the potential for host-level compromise, organizations should prioritize the deployment of the Chrome update across all managed Windows endpoints. Security teams must ensure that the update is applied to all instances of the browser, particularly those utilized within enterprise-managed environments where the vulnerable component is active.