CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-78909

unknowncovered by 2 sourcesfirst seen 2026-08-25
Use after free in Views in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

CSIRTS triage

What
Multiple vulnerabilities exist in Google Chrome affecting various subsystems and functionality.
Who is affected
All users running affected versions of Google Chrome across all platforms.
Urgency
Multiple unspecified Chrome vulnerabilities warrant prompt patching as the attack surface is broad and exploitation likelihood is high.
Action
Update Google Chrome to the latest available version immediately.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-78909

Get an email if CVE-2026-78909 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Advisory coverage (2)

External references

NVD record for CVE-2026-78909

CVE.org record

Embed the live status

CVE-2026-78909 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-78909 status](https://www.csirts.com/badge/CVE-2026-78909)](https://www.csirts.com/cve/CVE-2026-78909)