CVE-2026-78952

Google · Chrome

An out of bounds write vulnerability in the Google Chrome Crashpad component allows remote attackers to achieve arbitrary code execution outside the sandbox via a crafted HTML page.

Executive summary

Google Chrome versions prior to 152.0.7977.65 are vulnerable to a high severity out of bounds write flaw that enables remote code execution.

Vulnerability

This vulnerability is an out of bounds write (CWE-787) located in the Crashpad component. An unauthenticated remote attacker can trigger this flaw by enticing a user to navigate to a crafted HTML page, which then leverages a compromised renderer process to escape the browser sandbox.

Business impact

The ability to execute arbitrary code outside the browser sandbox poses a severe threat to endpoint integrity. Successful exploitation could lead to full system compromise, unauthorized data access, and the installation of persistent malware, effectively bypassing the primary security boundary of the browser. With a CVSS score of 8.3, this vulnerability represents a high risk to organizational assets.

Remediation

Immediate Action: Update all instances of Google Chrome to version 152.0.7977.65 or later immediately to apply the vendor-supplied security patch.

Proactive Monitoring: Monitor endpoint security logs for anomalous process behavior or unauthorized child processes spawned by the Chrome renderer.

Compensating Controls: Ensure that endpoint protection solutions, such as EDR or antivirus, are fully updated and configured to detect sandbox escape attempts or malicious script execution.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the severity of potential sandbox escapes, organizations should prioritize the deployment of the Chrome update across all managed workstations. Failure to address this vulnerability leaves endpoints exposed to remote code execution risks from malicious or compromised websites.

More Google CVEs

Sources