CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-78898

unknowncovered by 2 sourcesfirst seen 2026-08-25
Incorrect authorization in Downloads in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Medium)

CSIRTS triage

What
Multiple vulnerabilities exist in Google Chrome affecting various subsystems and functionality.
Who is affected
All users running affected versions of Google Chrome across all platforms.
Urgency
Multiple unspecified Chrome vulnerabilities warrant prompt patching as the attack surface is broad and exploitation likelihood is high.
Action
Update Google Chrome to the latest available version immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-78898

Get an email if CVE-2026-78898 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (2)

External references

NVD record for CVE-2026-78898

CVE.org record

Embed the live status

CVE-2026-78898 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-78898 status](https://www.csirts.com/badge/CVE-2026-78898)](https://www.csirts.com/cve/CVE-2026-78898)