Junglewise Threat Intelligence

CVE-2026-76018: Google Chrome privilege elevation in Import

CVE-2026-76018 · Severity: high · CVSS 8.8 · Published 2026-08-20

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contains a vulnerability in its import functionality that allows attackers to bypass security sandboxing. A remote attacker could trick a user into opening a malicious file, potentially gaining the ability to execute arbitrary code with elevated privileges outside Chrome's normal security boundaries, leading to complete system compromise.

Technical details

This vulnerability is a privilege elevation flaw in Chrome's Import component that permits sandbox escape. The attack requires social engineering to convince a user to open a crafted file via the import mechanism. By exploiting this flaw, an attacker can execute arbitrary code outside the sandboxed browser environment, achieving full code execution at the user's privilege level. The vulnerability was patched in Chrome version 151.0.7922.173 and later, released on August 20, 2026.

Affected products

  • Google Chrome prior to 151.0.7922.173

Timeline

  • 2026-08-20: disclosed: Published in Chrome 151.0.7922.173 stable release
  • 2026-08-20: patched: Fixed in Chrome 151.0.7922.173 and later

References

Related threats