DIRAS TAKE
High urgency: public exploit code exists for this Chrome V8 issue, so update immediately to the fixed release 152.0.7977.65 or apply mitigations to limit exposure.
What is CVE-2026-78938?
A remote attacker can trigger a type confusion flaw in the V8 JavaScript engine to run arbitrary code inside the Chrome sandbox on affected installations. CVE-2026-78938 affects Chrome 152.0.7977.65 and earlier builds in the 152.x branch (listed as 152.0.7977.65 – before 152.0.7977.65). Exploitation requires a user to load a specially crafted web page (user interaction) but does not require prior authentication; public exploit code is available.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Which versions of Google Chrome are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 152.x | 152.0.7977.65 – before 152.0.7977.65 | 152.0.7977.65 |
Is CVE-2026-78938 being exploited?
Public exploit code is available.
How to fix CVE-2026-78938
- Update Chrome to version 152.0.7977.65 (the vendor-provided fix).
- If immediate update is not possible, restrict access to untrusted web content and block unknown or suspicious sites at the network edge.
- Monitor endpoint and browser telemetry for crashes or anomalous process behavior related to V8 and investigate indicators of compromise.
- Enable automatic updates for Chrome and ensure users apply browser updates promptly.
Frequently asked questions
Is CVE-2026-78938 being actively exploited?
Public exploit code for CVE-2026-78938 is available, indicating a higher risk of active exploitation.
Which Chrome versions are affected by CVE-2026-78938?
Chrome builds in the 152.x branch prior to 152.0.7977.65 are affected; the vulnerable range is listed as 152.0.7977.65 – before 152.0.7977.65.
Is there a patch for CVE-2026-78938?
Yes. Google released a fix in Chrome version 152.0.7977.65.
Does CVE-2026-78938 require authentication?
No authentication is required, but exploitation requires user interaction (a user loading a crafted web page) to trigger the V8 type confusion.
References
- nvd.nist.gov/vuln/detail/CVE-2026-78938
- cve.org/CVERecord?id=CVE-2026-78938
- chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html
- issues.chromium.org/issues/545767601
- All Google CVEs on CVE Radar
- CVEs published in September 2026