CVE-2026-76018

Description

A flaw was found in Google Chrome's Import component. A remote attacker, leveraging social engineering tactics, could exploit this vulnerability by tricking a user into processing a specially crafted file. Successful exploitation could lead to privilege elevation, allowing the attacker to potentially execute arbitrary code outside the browser's security sandbox.

Statement

Red Hat does not ship Google Chrome or Chromium as part of any supported Red Hat product. Chromium is available through EPEL, which is community-maintained and outside Red Hat's production support scope. Electron is shipped in some Red Hat products (podman-desktop, RHEL 10), but the affected Import component is Chrome browser-specific UI functionality not present in Electron's embedded Chromium engine.

Understanding the Weakness (CWE)

Integrity,Confidentiality,Availability

Technical Impact: Execute Unauthorized Code or Commands

Execution of arbitrary code in the context of usage of the resources with dangerous names.

Confidentiality,Availability

Technical Impact: Read Application Data; DoS: Crash, Exit, or Restart

Crash of the consumer code of these resources resulting in information leakage or denial of service.

Frequently Asked Questions

Want to get errata notifications? Sign up here.