CVE-2026-78999

Google · Chrome

Google Chrome contains a privilege management flaw in Navigation, allowing remote attackers to potentially execute arbitrary code outside the sandbox via a crafted HTML page.

Executive summary

A critical privilege management vulnerability in Google Chrome allows remote attackers to escape the browser sandbox and execute arbitrary code, posing a severe risk to end-user systems.

Vulnerability

The vulnerability involves improper privilege management within the browser navigation component, which can be triggered by an unauthenticated remote attacker who has already compromised the renderer process and successfully employs social engineering tactics. This flaw enables the attacker to break out of the browser sandbox environment.

Business impact

The ability to execute arbitrary code outside the browser sandbox represents a significant threat to organizational security, as it allows attackers to gain full control over the affected endpoint. Given the CVSS score of 8.3, this high-severity vulnerability could lead to widespread data exfiltration, the deployment of persistent malware, or lateral movement within the corporate network.

Remediation

Immediate Action: Update all instances of Google Chrome to version 152.0.7977.65 or later immediately.

Proactive Monitoring: Review endpoint security logs for unusual process spawning activities originating from the browser or unauthorized attempts to access system-level files.

Compensating Controls: Deploy browser-based security policies that restrict navigation to trusted domains and utilize advanced endpoint detection and response (EDR) solutions to monitor for sandbox escape behaviors.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the severity of sandbox escape vulnerabilities and the high CVSS score, organizations must prioritize patching all Chrome installations. Security teams should ensure the update is pushed via automated deployment tools to minimize the window of exposure for end users.

More Google CVEs

Sources