• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-78904: remote code execution in Google Chrome

Remote attackers can execute code in Chrome by exploiting a type confusion flaw in ANGLE; this is tracked as CVE-2026-78904. The bug affects Chrome 152.x builds before 152.0.7977.65; the vendor fixed the issue in 152.0.7977.65. Exploitation requires delivering crafted web content to a targeted user (the CVSS vector indicates network attack with user interaction), so an attacker must get a user to load a malicious page or content in the vulnerable Chrome version.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.6CRITICAL
EPSS
0.00503
CWE
CWE-843
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent — public exploit code is available for CVE-2026-78904, so update Chrome to 152.0.7977.65 immediately or otherwise block access to vulnerable builds until patched.

What is CVE-2026-78904?

Remote attackers can execute code in Chrome by exploiting a type confusion flaw in ANGLE; this is tracked as CVE-2026-78904. The bug affects Chrome 152.x builds before 152.0.7977.65; the vendor fixed the issue in 152.0.7977.65. Exploitation requires delivering crafted web content to a targeted user (the CVSS vector indicates network attack with user interaction), so an attacker must get a user to load a malicious page or content in the vulnerable Chrome version.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Which versions of Google Chrome are affected?

BRANCHAFFECTEDFIXED
152.x152.0.7977.65 – before 152.0.7977.65152.0.7977.65

Is CVE-2026-78904 being exploited?

Public exploit code is available.

How to fix CVE-2026-78904

  1. Update Chrome to 152.0.7977.65 (the fixed release) on all endpoints.
  2. Block or restrict access to untrusted web content and disable risky web features via enterprise policies until updates are applied.
  3. Monitor endpoint telemetry for browser crashes or unusual renderer activity and investigate users running pre-152.0.7977.65 builds.
  4. Apply vendor guidance and roll out the patch through your standard update channels as soon as possible.

Frequently asked questions

Is CVE-2026-78904 being actively exploited?

Public exploit code exists for CVE-2026-78904 as of 2026-09-29, but there are no public reports in the provided facts confirming active exploitation in the wild as of that date.

Which Chrome versions are affected by CVE-2026-78904?

Chrome 152.x releases before 152.0.7977.65 are affected; the issue is fixed in 152.0.7977.65.

Is there a patch for CVE-2026-78904?

Yes. Google fixed the vulnerability in Chrome version 152.0.7977.65.

Does CVE-2026-78904 require authentication?

No authentication is required; an attacker only needs to supply crafted web content and a user must load it in a vulnerable Chrome build (user interaction is required).

References