CVE-2026-76018
Description
A flaw was found in Google Chrome's Import component. A remote attacker, leveraging social engineering tactics, could exploit this vulnerability by tricking a user into processing a specially crafted file. Successful exploitation could lead to privilege elevation, allowing the attacker to potentially execute arbitrary code outside the browser's security sandbox.
Statement
Red Hat does not ship Google Chrome or Chromium as part of any supported Red Hat product. Chromium is available through EPEL, which is community-maintained and outside Red Hat's production support scope. Electron is shipped in some Red Hat products (podman-desktop, RHEL 10), but the affected Import component is Chrome browser-specific UI functionality not present in Electron's embedded Chromium engine.
Understanding the Weakness (CWE)
Integrity,Confidentiality,Availability
Technical Impact: Execute Unauthorized Code or Commands
Execution of arbitrary code in the context of usage of the resources with dangerous names.
Confidentiality,Availability
Technical Impact: Read Application Data; DoS: Crash, Exit, or Restart
Crash of the consumer code of these resources resulting in information leakage or denial of service.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.