CVE-2026-78952
Google · Chrome
An out of bounds write vulnerability in the Google Chrome Crashpad component allows remote attackers to achieve arbitrary code execution outside the sandbox via a crafted HTML page.
Executive summary
Google Chrome versions prior to 152.0.7977.65 are vulnerable to a high severity out of bounds write flaw that enables remote code execution.
Vulnerability
This vulnerability is an out of bounds write (CWE-787) located in the Crashpad component. An unauthenticated remote attacker can trigger this flaw by enticing a user to navigate to a crafted HTML page, which then leverages a compromised renderer process to escape the browser sandbox.
Business impact
The ability to execute arbitrary code outside the browser sandbox poses a severe threat to endpoint integrity. Successful exploitation could lead to full system compromise, unauthorized data access, and the installation of persistent malware, effectively bypassing the primary security boundary of the browser. With a CVSS score of 8.3, this vulnerability represents a high risk to organizational assets.
Remediation
Immediate Action: Update all instances of Google Chrome to version 152.0.7977.65 or later immediately to apply the vendor-supplied security patch.
Proactive Monitoring: Monitor endpoint security logs for anomalous process behavior or unauthorized child processes spawned by the Chrome renderer.
Compensating Controls: Ensure that endpoint protection solutions, such as EDR or antivirus, are fully updated and configured to detect sandbox escape attempts or malicious script execution.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the severity of potential sandbox escapes, organizations should prioritize the deployment of the Chrome update across all managed workstations. Failure to address this vulnerability leaves endpoints exposed to remote code execution risks from malicious or compromised websites.