CVE-2026-78985

Google · Chrome

An incorrect reference resolution vulnerability in the Google Chrome FileSystem component allows remote attackers to achieve arbitrary code execution outside the sandbox via social engineering.

Executive summary

A critical vulnerability in Google Chrome allows remote attackers to execute arbitrary code outside the browser sandbox by leveraging social engineering tactics.

Vulnerability

The flaw is caused by incorrect reference resolution within the FileSystem component, which can be triggered by an unauthenticated remote attacker using a crafted HTML page to bypass sandbox protections.

Business impact

The potential for arbitrary code execution outside the browser sandbox poses a severe risk to organizational assets, as it allows attackers to move from the browser environment to the underlying host system. While the vendor classifies the Chromium security severity as Medium, the CVSS score of 9.6 reflects the critical nature of potential system compromise and data exfiltration. Successful exploitation could lead to full system takeover, resulting in significant reputational damage and loss of sensitive information.

Remediation

Immediate Action: Update Google Chrome to version 152.0.7977.65 or later to apply the necessary security patches.

Proactive Monitoring: Review endpoint security logs for anomalous processes spawned by the browser and monitor for unusual network activity originating from user workstations.

Compensating Controls: Deploy endpoint detection and response (EDR) solutions to identify and block unauthorized shell commands or suspicious file system modifications.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical CVSS score of 9.6 and the potential for full system compromise, immediate patching is required for all Chrome installations. Administrators should prioritize deployment across the organization to neutralize the risk of sandbox escape and subsequent code execution.

More Google CVEs

Sources