CVE-2026-76044

Description

A flaw was found in Google Chrome's USB component. A remote attacker, after compromising the renderer process, could exploit a race condition by using a specially crafted HTML page. This could potentially lead to the execution of arbitrary code outside of the browser's security sandbox, allowing the attacker to gain further control over the system.

Statement

This Important flaw in the chromium-browser package allows a remote attacker to execute arbitrary code outside the browser's sandbox. Exploitation requires a compromised renderer process and user interaction with a specially crafted HTML page, enabling a significant security bypass.

Understanding the Weakness (CWE)

Integrity,Confidentiality

Technical Impact: Modify Application Data; Read Application Data

Frequently Asked Questions

Want to get errata notifications? Sign up here.