CVE-2026-76020
Google Chrome vulnerability analysis and mitigation

Overview

CVE-2026-76020 is a race condition vulnerability in the V8 JavaScript engine of Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. It was reported by Salvatore Gulizia (nickname: Serotav) on August 3, 2026, and publicly disclosed on August 20, 2026, alongside the Chrome 151.0.7922.173 stable channel release. All versions of Google Chrome prior to 151.0.7922.173 are affected. The vulnerability carries a Chromium security severity rating of High, though a formal CVSS base score has not yet been assigned (EPSS: 0.0) (Chrome Releases, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-367 (Time-of-check Time-of-use / TOCTOU Race Condition), where the V8 engine checks the state of a resource before using it, but the resource's state can change between the check and the use in a way that invalidates the check's results. An attacker exploits this by delivering a specially crafted HTML page that triggers the race condition in V8's execution path, achieving arbitrary code execution within the Chrome sandbox without requiring any user authentication beyond visiting the malicious page. The Chromium issue tracker entry is tracked at issue #541837151, though full technical details remain restricted pending broad user patch adoption (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation allows a remote, unauthenticated attacker to execute arbitrary code within the Chrome sandbox by luring a victim to a malicious webpage. While execution is confined to the sandbox, this represents a significant stepping stone for further exploitation — particularly if chained with a sandbox escape vulnerability, which could lead to full system compromise, data exfiltration, or lateral movement. The attack requires no special privileges or user interaction beyond visiting a crafted HTML page (Chrome Releases, GitHub Advisory).

Exploitability

As of the disclosure date (August 20, 2026), there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is 0.0, reflecting low current exploitation probability, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported at this time (GitHub Advisory).

Mitigation and workarounds

Google has released a patch in Chrome stable channel version 151.0.7922.173 for Linux and 151.0.7922.173/.174 for Windows and Mac. Users should immediately update Google Chrome to version 151.0.7922.173 or later via the browser's built-in update mechanism (Settings → Help → About Google Chrome) or by enabling automatic updates. As a temporary workaround where immediate patching is not feasible, organizations should restrict user access to untrusted or unknown websites (Chrome Releases, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Google Chrome vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76023NONEN/A
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesAug 20, 2026
CVE-2026-76022NONEN/A
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesAug 20, 2026
CVE-2026-76021NONEN/A
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesAug 20, 2026
CVE-2026-76020NONEN/A
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesAug 20, 2026
CVE-2026-76019NONEN/A
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management