DIRAS TAKE
Urgent — public exploit code is available for CVE-2026-78904, so update Chrome to 152.0.7977.65 immediately or otherwise block access to vulnerable builds until patched.
What is CVE-2026-78904?
Remote attackers can execute code in Chrome by exploiting a type confusion flaw in ANGLE; this is tracked as CVE-2026-78904. The bug affects Chrome 152.x builds before 152.0.7977.65; the vendor fixed the issue in 152.0.7977.65. Exploitation requires delivering crafted web content to a targeted user (the CVSS vector indicates network attack with user interaction), so an attacker must get a user to load a malicious page or content in the vulnerable Chrome version.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Which versions of Google Chrome are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 152.x | 152.0.7977.65 – before 152.0.7977.65 | 152.0.7977.65 |
Is CVE-2026-78904 being exploited?
Public exploit code is available.
How to fix CVE-2026-78904
- Update Chrome to 152.0.7977.65 (the fixed release) on all endpoints.
- Block or restrict access to untrusted web content and disable risky web features via enterprise policies until updates are applied.
- Monitor endpoint telemetry for browser crashes or unusual renderer activity and investigate users running pre-152.0.7977.65 builds.
- Apply vendor guidance and roll out the patch through your standard update channels as soon as possible.
Frequently asked questions
Is CVE-2026-78904 being actively exploited?
Public exploit code exists for CVE-2026-78904 as of 2026-09-29, but there are no public reports in the provided facts confirming active exploitation in the wild as of that date.
Which Chrome versions are affected by CVE-2026-78904?
Chrome 152.x releases before 152.0.7977.65 are affected; the issue is fixed in 152.0.7977.65.
Is there a patch for CVE-2026-78904?
Yes. Google fixed the vulnerability in Chrome version 152.0.7977.65.
Does CVE-2026-78904 require authentication?
No authentication is required; an attacker only needs to supply crafted web content and a user must load it in a vulnerable Chrome build (user interaction is required).
References
- nvd.nist.gov/vuln/detail/CVE-2026-78904
- cve.org/CVERecord?id=CVE-2026-78904
- chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html
- issues.chromium.org/issues/537835609
- All Google CVEs on CVE Radar
- CVEs published in September 2026