DIRAS TAKE
Urgent: public exploit code exists for this Chrome ANGLE bug, so update to 152.0.7977.65 immediately and restrict exposure until systems are patched.
What is CVE-2026-78906?
A remote attacker can execute arbitrary code in Google Chrome via a race condition in ANGLE; this is tracked as CVE-2026-78906. The flaw affects Chrome 152.x releases prior to the fixed build 152.0.7977.65. Exploitation requires a victim to load a crafted HTML page (user interaction) and does not require an account; the attack can lead to code running outside the browser sandbox.
Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Which versions of Google Chrome are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 152.x | 152.0.7977.65 – before 152.0.7977.65 | 152.0.7977.65 |
Is CVE-2026-78906 being exploited?
Public exploit code is available.
How to fix CVE-2026-78906
- Install the Chrome update 152.0.7977.65 which contains the fix.
- Block or limit access to untrusted web content and script execution via browser policy until patched.
- Monitor endpoints and browser crash logs for signs of exploitation and suspicious renderer activity.
Frequently asked questions
Is CVE-2026-78906 being actively exploited?
Public exploit code is available for CVE-2026-78906.
Which Chrome versions are affected by CVE-2026-78906?
Chrome 152.x releases before 152.0.7977.65 are affected by CVE-2026-78906.
Is there a patch for CVE-2026-78906?
Yes, Google released the fix in Chrome build 152.0.7977.65.
Does CVE-2026-78906 require authentication?
No, CVE-2026-78906 does not require an account; it requires a user to load a crafted HTML page in Chrome.
References
- nvd.nist.gov/vuln/detail/CVE-2026-78906
- cve.org/CVERecord?id=CVE-2026-78906
- chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html
- issues.chromium.org/issues/513923164
- All Google CVEs on CVE Radar
- CVEs published in September 2026