Description
Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-25
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution via USB Misauthorization
Action: Immediate Patch
AI Analysis

Impact

Incorrect authorization handling for USB devices in Google Chrome prior to version 152.0.7977.65 allows an attacker who has already compromised the renderer process to potentially escape the sandbox and execute arbitrary code on the host. The vulnerability manifests as a privilege escalation flaw (CWE-863) that can be triggered by a crafted HTML page and leveraged through social engineering. If successful, the attacker could gain full control of the system, bypassing Chrome’s sandboxed environment.

Affected Systems

All installations of Google Chrome running any version older than 152.0.7977.65 on supported operating systems are affected. This includes desktop builds for Windows, macOS, Linux, and Android.

Risk and Exploitability

The vulnerability has a CVSS score of 8.3 and is rated as high severity by Chromium’s internal scoring, indicating a significant impact. The EPSS score is < 1%, indicating a low but nonzero exploitation probability, but the combination of remote code execution potential and the need for a renderer process compromise suggests meaningful exploitability in environments lacking strong process isolation or where attackers can persuade users to open malicious content. The vulnerability is not listed in the CISA KEV catalog, but its existence in a widely deployed browser warrants prompt remediation.

Generated by OpenCVE AI on August 26, 2026 at 19:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or later to apply the fix.
  • Enable Chrome’s enterprise policy that restricts USB device access (or use a script to block USB access for Chrome processes) until the update is applied.
  • Verify that no legacy versions of Chrome are installed on critical endpoints and enforce automatic updates to ensure the vulnerability is remediated.

Generated by OpenCVE AI on August 26, 2026 at 19:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Title USB Access Misauthorization Enabling Sandbox Escape in Chrome

Wed, 26 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Wed, 26 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Title USB Access Misauthorization Enabling Sandbox Escape in Chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in USB in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:58:16.113Z

Reserved: 2026-08-25T06:04:06.822Z

Link: CVE-2026-78911

cve-icon Vulnrichment

Updated: 2026-08-26T16:37:42.631Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:48.590

Modified: 2026-08-27T16:23:22.390

Link: CVE-2026-78911

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T19:30:05Z

Weaknesses