SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-78901

HIGH · CVSS 7.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A race condition in the V8 JavaScript engine of Google Chrome prior to version 152.0.7977.65 enables remote attackers to execute arbitrary code within the browser's sandbox by leveraging a specially crafted HTML page. This vulnerability poses a medium security risk, making it essential for organizations using affected versions of Chrome to prioritize updates to mitigate potential exploitation. Users and administrators should ensure their browsers are up-to-date to protect against this threat.

CVE
CVE-2026-78901
Severity
HIGH
CVSS
7.5
EPSS
0.25%
Chrome

Original NVD Description

Race condition in V8 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Related CVEs

Other vulnerabilities affecting the same vendor(s)