Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-76044

Опубликовано: 18 авг. 2026
Источник: redhat
CVSS3: 9

Описание

Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

A flaw was found in Google Chrome's USB component. A remote attacker, after compromising the renderer process, could exploit a race condition by using a specially crafted HTML page. This could potentially lead to the execution of arbitrary code outside of the browser's security sandbox, allowing the attacker to gain further control over the system.

Отчет

This Important flaw in the chromium-browser package allows a remote attacker to execute arbitrary code outside the browser's sandbox. Exploitation requires a compromised renderer process and user interaction with a specially crafted HTML page, enabling a significant security bypass.

Дополнительная информация

Статус:

Important
Дефект:
CWE-368
https://bugzilla.redhat.com/show_bug.cgi?id=2518264chromium-browser: Google Chrome: Arbitrary code execution due to a race condition in USB

9 Critical

CVSS3

Связанные уязвимости

CVSS3: 8.3
ubuntu
около 1 месяца назад

Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

CVSS3: 8.3
nvd
около 1 месяца назад

Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

msrc
28 дней назад

Chromium: CVE-2026-76044 Race condition in USB

CVSS3: 8.3
debian
около 1 месяца назад

Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed ...

CVSS3: 8.3
github
около 1 месяца назад

Race condition in USB in Google Chrome prior to 151.0.7922.169 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)

9 Critical

CVSS3