DIRAS TAKE
Urgently update affected Chrome installs because public exploit code exists for this ANGLE type confusion; applying the fixed build 152.0.7977.65 removes the vulnerability.
What is CVE-2026-78905?
An attacker can run arbitrary code in Google Chrome by inducing a type confusion in ANGLE when a user visits a specially crafted web page. CVE-2026-78905 affects Chrome 152.x builds prior to the fixed release 152.0.7977.65; the vendor lists 152.0.7977.65 as the fixed version. Exploitation requires user interaction (the victim must load the malicious page) and can lead to code execution outside the browser sandbox.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Which versions of Google Chrome are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 152.x | 152.0.7977.65 – before 152.0.7977.65 | 152.0.7977.65 |
Is CVE-2026-78905 being exploited?
Public exploit code is available.
How to fix CVE-2026-78905
- Upgrade Chrome to 152.0.7977.65 or later on all affected systems.
- Block or limit access to untrusted web content where possible and enforce safe browsing and content filtering.
- Monitor endpoints for signs of compromise and unusual child processes spawned by Chrome.
- Follow Google's security guidance and apply enterprise deployment policies to accelerate the update rollout.
Frequently asked questions
Is CVE-2026-78905 being actively exploited?
Public exploit code is available for CVE-2026-78905.
Which Chrome versions are affected by CVE-2026-78905?
Chrome 152.x builds before 152.0.7977.65 are affected; the vendor marks 152.0.7977.65 as the fixed version.
Is there a patch for CVE-2026-78905?
Yes. Google fixed the issue in Chrome version 152.0.7977.65.
Does CVE-2026-78905 require authentication?
No authentication is required, but exploitation requires user interaction: the victim must load a crafted web page in Chrome.
References
- nvd.nist.gov/vuln/detail/CVE-2026-78905
- cve.org/CVERecord?id=CVE-2026-78905
- chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html
- issues.chromium.org/issues/517245017
- All Google CVEs on CVE Radar
- CVEs published in September 2026