CVE-2026-78911: Incorrect authorization in Google Chrome
Description
CVE-2026-78911 is a high-severity vulnerability in Google Chrome prior to version 152.0.7977.65 involving incorrect authorization in USB handling. A remote attacker who has compromised the renderer process and uses social engineering could potentially execute arbitrary code outside the sandbox via a crafted HTML page. The vulnerability affects Chrome desktop versions before 152.0.7977.65.
CVSS v3.1
Score 8.3high
Affected software
Chrome
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves incorrect authorization in the USB component of Google Chrome before version 152.0.7977.65. An attacker who has already compromised the renderer process and employs social engineering techniques may exploit this flaw to execute arbitrary code outside the browser sandbox by delivering a crafted HTML page. The issue is rated with a CVSS 3.1 base score of 8.3, indicating high severity. There is no explicit vendor advisory text on remediation level, but the vulnerability is fixed in version 152.0.7977.65 as indicated by the affected versions and the referenced Chrome stable channel update blog post.
Potential Impact
Successful exploitation could allow remote code execution outside the sandbox, leading to full compromise of the affected system. The attacker must have already compromised the renderer process and use social engineering to trigger the exploit. This elevates the risk of arbitrary code execution with high confidentiality, integrity, and availability impact.
Mitigation Recommendations
Users should update Google Chrome to version 152.0.7977.65 or later to remediate this vulnerability. The vendor advisory linked confirms the availability of a stable channel update addressing this issue. No additional mitigation steps are indicated by the vendor advisory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Chrome
- Date Reserved
- 2026-08-25T06:04:06.822Z
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0256176589.html","vendor":"Google"}]
Threat ID: 6a8df9b7acd9273b49ac6d7b
Added to database: 08/25/2026, 20:23:19 UTC
Last enriched: 09/10/2026, 00:52:33 UTC
Last updated: 10/10/2026, 06:48:19 UTC
Views: 32
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.