Description
Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper input validation flaw in the Media component of Google Chrome before version 152.0.7977.65. A malicious actor can craft a specially formatted HTML page that, when opened by a user, may lead to the execution of arbitrary code outside the browser's sandbox. This permits full compromise of the affected system. The flaw is classified by Chromium as a Medium severity issue, but the CVSS score of 8.8 indicates a high impact.

Affected Systems

Google Chrome on desktop platforms running any version earlier than 152.0.7977.65 is affected. The vulnerability originates in the Media subsystem, which processes multimedia content presented in HTML pages.

Risk and Exploitability

Because the exploit requires a user to open a crafted HTML page, exploitation is remote but opportunistic. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, indicating that widespread exploitation has not yet been observed. The CVSS score of 8.8 and the classification of remote code execution suggest a high risk if an attacker can convince a user to visit a malicious page, although it does not represent an automatically exploitable flaw like server-side vulnerabilities.

Generated by OpenCVE AI on August 26, 2026 at 14:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Google Chrome 152.0.7977.65 or later
  • Configure Chrome to block or restrict loading of media content from untrusted sources, such as by applying a Content Security Policy that disallows media tags on suspicious sites
  • Enable Chrome Safe Browsing and enforce strict content settings to reduce exposure to malicious media

Generated by OpenCVE AI on August 26, 2026 at 14:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Improper input validation in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:56:27.504Z

Reserved: 2026-08-25T06:10:59.347Z

Link: CVE-2026-79182

cve-icon Vulnrichment

Updated: 2026-08-26T12:50:32.316Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:11.813

Modified: 2026-08-27T13:14:33.220

Link: CVE-2026-79182

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T15:00:07Z

Weaknesses
  • CWE-20

    Improper Input Validation