CVE-2026-78978

8.8

Google · Chrome

An out of bounds read flaw in the ANGLE component of Google Chrome on Windows allows remote attackers to execute arbitrary code via a crafted HTML page.

Executive summary

A high severity out of bounds read vulnerability in Google Chrome on Windows poses a significant risk of remote code execution for unauthenticated users.

Vulnerability

This vulnerability is an out of bounds read error within the ANGLE graphics engine component. An unauthenticated remote attacker can trigger this flaw by enticing a user to visit a specially crafted HTML page, potentially leading to arbitrary code execution outside of the browser sandbox.

Business impact

The potential for remote code execution represents a critical risk to organizational security, as it could allow an attacker to bypass browser protections and compromise the local workstation. Given the CVSS score of 8.8, this vulnerability is classified as high severity, indicating that successful exploitation could result in significant data loss or unauthorized system access.

Remediation

Immediate Action: Update all Google Chrome instances on Windows to version 152.0.7977.65 or later immediately.

Proactive Monitoring: Review endpoint security logs for unusual browser activity or unexpected process spawns associated with the Chrome application.

Compensating Controls: Deploy endpoint protection platforms that utilize heuristic analysis to detect and block malicious code execution attempts originating from web browser processes.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the nature of the vulnerability, organizations should prioritize the deployment of the latest Chrome security updates across their environment. Users should be cautioned against navigating to untrusted websites until the update is successfully applied to all managed devices.

More Google CVEs

Sources