• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-78938: pre-auth remote code execution in Google Chrome

A remote attacker can trigger a type confusion flaw in the V8 JavaScript engine to run arbitrary code inside the Chrome sandbox on affected installations. CVE-2026-78938 affects Chrome 152.0.7977.65 and earlier builds in the 152.x branch (listed as 152.0.7977.65 – before 152.0.7977.65). Exploitation requires a user to load a specially crafted web page (user interaction) but does not require prior authentication; public exploit code is available.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
8.8HIGH
EPSS
0.00451
CWE
CWE-843
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

High urgency: public exploit code exists for this Chrome V8 issue, so update immediately to the fixed release 152.0.7977.65 or apply mitigations to limit exposure.

What is CVE-2026-78938?

A remote attacker can trigger a type confusion flaw in the V8 JavaScript engine to run arbitrary code inside the Chrome sandbox on affected installations. CVE-2026-78938 affects Chrome 152.0.7977.65 and earlier builds in the 152.x branch (listed as 152.0.7977.65 – before 152.0.7977.65). Exploitation requires a user to load a specially crafted web page (user interaction) but does not require prior authentication; public exploit code is available.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Which versions of Google Chrome are affected?

BRANCHAFFECTEDFIXED
152.x152.0.7977.65 – before 152.0.7977.65152.0.7977.65

Is CVE-2026-78938 being exploited?

Public exploit code is available.

How to fix CVE-2026-78938

  1. Update Chrome to version 152.0.7977.65 (the vendor-provided fix).
  2. If immediate update is not possible, restrict access to untrusted web content and block unknown or suspicious sites at the network edge.
  3. Monitor endpoint and browser telemetry for crashes or anomalous process behavior related to V8 and investigate indicators of compromise.
  4. Enable automatic updates for Chrome and ensure users apply browser updates promptly.

Frequently asked questions

Is CVE-2026-78938 being actively exploited?

Public exploit code for CVE-2026-78938 is available, indicating a higher risk of active exploitation.

Which Chrome versions are affected by CVE-2026-78938?

Chrome builds in the 152.x branch prior to 152.0.7977.65 are affected; the vulnerable range is listed as 152.0.7977.65 – before 152.0.7977.65.

Is there a patch for CVE-2026-78938?

Yes. Google released a fix in Chrome version 152.0.7977.65.

Does CVE-2026-78938 require authentication?

No authentication is required, but exploitation requires user interaction (a user loading a crafted web page) to trigger the V8 type confusion.

References