Description
Incorrect authorization in Sandbox in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-25
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Now
AI Analysis

Impact

Incorrect authorization in the Chrome sandbox allows a remote attacker who has already compromised the renderer process to execute arbitrary code outside the sandbox. This flaw effectively removes the security boundary that contains renderer activity, enabling the attacker to run malicious code with the privileges of the browser process. The weakness is an improper authorization flaw (CWE‑863) and the stated Chromium severity is High.

Affected Systems

The vulnerability applies to Google Chrome browsers that are earlier than version 152.0.7977.65. Version information is limited to the pre‑152.0.7977.65 release series, so any older release may be affected. No specific build or patch list is supplied beyond the cutoff.

Risk and Exploitability

At the time of analysis the EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is 8.3, indicating a high severity, and the intrinsic Chromium severity is High, implying a serious risk. Exploitation requires the attacker to first compromise the renderer process and then deliver a specially crafted HTML page. While the exact likelihood of exploitation is not quantified, the high severity and remote code execution nature suggest that the threat is significant for exposed systems.

Generated by OpenCVE AI on August 26, 2026 at 20:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or newer, which removes the faulty sandbox authorization logic.
  • Disable or heavily restrict third‑party extensions that may run with renderer privileges to reduce the chance of renderer compromise.
  • Use enterprise software restriction or application control policies to block execution of untrusted renderer processes and prevent execution of external content.
  • Apply network segmentation or web filtering to limit user access to potentially malicious HTML content that could trigger the flaw.

Generated by OpenCVE AI on August 26, 2026 at 20:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Sandbox Authorization Bypass Leading to Remote Code Execution in Google Chrome

Wed, 26 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Wed, 26 Aug 2026 04:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 03:30:00 +0000

Type Values Removed Values Added
Title Sandbox Authorization Bypass Leading to Remote Code Execution in Google Chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Sandbox in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T03:58:14.641Z

Reserved: 2026-08-25T06:11:49.952Z

Link: CVE-2026-79218

cve-icon Vulnrichment

Updated: 2026-08-26T16:37:03.353Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:15.867

Modified: 2026-08-27T04:17:50.557

Link: CVE-2026-79218

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T20:30:11Z

Weaknesses