Junglewise Threat Intelligence

CVE-2026-78952: Google Chrome out of bounds write in Crashpad on Windows

CVE-2026-78952 · Severity: high · CVSS 8.3 · Published 2026-08-25

Technologies: Microsoft Windows, Google Chrome. Vendors: Microsoft, Google.

Executive brief

Google Chrome's Crashpad component on Windows contains an out-of-bounds memory write vulnerability that allows attackers to execute arbitrary code outside the browser's sandbox. An attacker who has already compromised the renderer process can exploit this via a malicious webpage to break out of the sandbox and gain full system access.

Technical details

An out-of-bounds write flaw exists in Crashpad, Google Chrome's crash reporting component, affecting the Windows platform. The vulnerability allows a remote attacker who has already compromised the renderer process to write data beyond allocated buffer boundaries via a crafted HTML page, leading to code execution outside the sandbox. This requires the attacker to have already achieved renderer process compromise, but enables sandbox escape and arbitrary code execution with system privileges. The vulnerability was fixed in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome before 152.0.7977.65 on Windows

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats