Junglewise Threat Intelligence

CVE-2026-78900: Google Chrome improper input validation in Media component

CVE-2026-78900 · Severity: critical · CVSS 9.6 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used by billions of users to access websites and web applications. An improper input validation flaw in Chrome's Media component allows a remote attacker to execute arbitrary code outside the browser's security sandbox by visiting a malicious webpage, potentially leading to complete compromise of the user's system including data theft and installation of malware.

Technical details

This vulnerability is an improper input validation issue in the Media component of Google Chrome prior to version 152.0.7977.65. The flaw allows a remote attacker to bypass the browser's sandbox protection mechanism through a crafted HTML page, achieving arbitrary code execution with the privileges of the browser process. The attack vector is network-based and requires only that a user visit a malicious website; no authentication or user interaction beyond normal browsing is required. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65

References

Related threats