CVE-2026-76044
Description
A flaw was found in Google Chrome's USB component. A remote attacker, after compromising the renderer process, could exploit a race condition by using a specially crafted HTML page. This could potentially lead to the execution of arbitrary code outside of the browser's security sandbox, allowing the attacker to gain further control over the system.
Statement
This Important flaw in the chromium-browser package allows a remote attacker to execute arbitrary code outside the browser's sandbox. Exploitation requires a compromised renderer process and user interaction with a specially crafted HTML page, enabling a significant security bypass.
Understanding the Weakness (CWE)
Integrity,Confidentiality
Technical Impact: Modify Application Data; Read Application Data
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.