• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-78906: remote code execution in Google Chrome

A remote attacker can execute arbitrary code in Google Chrome via a race condition in ANGLE; this is tracked as CVE-2026-78906. The flaw affects Chrome 152.x releases prior to the fixed build 152.0.7977.65. Exploitation requires a victim to load a crafted HTML page (user interaction) and does not require an account; the attack can lead to code running outside the browser sandbox.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.5HIGH
EPSS
0.00289
CWE
CWE-362
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists for this Chrome ANGLE bug, so update to 152.0.7977.65 immediately and restrict exposure until systems are patched.

What is CVE-2026-78906?

A remote attacker can execute arbitrary code in Google Chrome via a race condition in ANGLE; this is tracked as CVE-2026-78906. The flaw affects Chrome 152.x releases prior to the fixed build 152.0.7977.65. Exploitation requires a victim to load a crafted HTML page (user interaction) and does not require an account; the attack can lead to code running outside the browser sandbox.

Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Which versions of Google Chrome are affected?

BRANCHAFFECTEDFIXED
152.x152.0.7977.65 – before 152.0.7977.65152.0.7977.65

Is CVE-2026-78906 being exploited?

Public exploit code is available.

How to fix CVE-2026-78906

  1. Install the Chrome update 152.0.7977.65 which contains the fix.
  2. Block or limit access to untrusted web content and script execution via browser policy until patched.
  3. Monitor endpoints and browser crash logs for signs of exploitation and suspicious renderer activity.

Frequently asked questions

Is CVE-2026-78906 being actively exploited?

Public exploit code is available for CVE-2026-78906.

Which Chrome versions are affected by CVE-2026-78906?

Chrome 152.x releases before 152.0.7977.65 are affected by CVE-2026-78906.

Is there a patch for CVE-2026-78906?

Yes, Google released the fix in Chrome build 152.0.7977.65.

Does CVE-2026-78906 require authentication?

No, CVE-2026-78906 does not require an account; it requires a user to load a crafted HTML page in Chrome.

References