Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76018

Опубликовано: 20 авг. 2026
Источник: redhat
CVSS3: 9.6

Описание

Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted file. (Chromium security severity: High)

A flaw was found in Google Chrome's Import component. A remote attacker, leveraging social engineering tactics, could exploit this vulnerability by tricking a user into processing a specially crafted file. Successful exploitation could lead to privilege elevation, allowing the attacker to potentially execute arbitrary code outside the browser's security sandbox.

Отчет

Red Hat does not ship Google Chrome or Chromium as part of any supported Red Hat product. Chromium is available through EPEL, which is community-maintained and outside Red Hat's production support scope. Electron is shipped in some Red Hat products (podman-desktop, RHEL 10), but the affected Import component is Chrome browser-specific UI functionality not present in Electron's embedded Chromium engine.

Дополнительная информация

Статус:

Important
Дефект:
CWE-641
https://bugzilla.redhat.com/show_bug.cgi?id=2520790chromium-browser: Google Chrome: Arbitrary Code Execution via crafted file in Import component

9.6 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
28 дней назад

Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted file. (Chromium security severity: High)

CVSS3: 8.8
nvd
28 дней назад

Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted file. (Chromium security severity: High)

msrc
6 дней назад

Chromium CVE-2026-76018: Privilege elevation in Import

CVSS3: 8.8
debian
28 дней назад

Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 ...

CVSS3: 8.8
github
28 дней назад

Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted file. (Chromium security severity: High)

9.6 Critical

CVSS3