
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-76020 is a race condition vulnerability in the V8 JavaScript engine of Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. It was reported by Salvatore Gulizia (nickname: Serotav) on August 3, 2026, and publicly disclosed on August 20, 2026, alongside the Chrome 151.0.7922.173 stable channel release. All versions of Google Chrome prior to 151.0.7922.173 are affected. The vulnerability carries a Chromium security severity rating of High, though a formal CVSS base score has not yet been assigned (EPSS: 0.0) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-367 (Time-of-check Time-of-use / TOCTOU Race Condition), where the V8 engine checks the state of a resource before using it, but the resource's state can change between the check and the use in a way that invalidates the check's results. An attacker exploits this by delivering a specially crafted HTML page that triggers the race condition in V8's execution path, achieving arbitrary code execution within the Chrome sandbox without requiring any user authentication beyond visiting the malicious page. The Chromium issue tracker entry is tracked at issue #541837151, though full technical details remain restricted pending broad user patch adoption (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote, unauthenticated attacker to execute arbitrary code within the Chrome sandbox by luring a victim to a malicious webpage. While execution is confined to the sandbox, this represents a significant stepping stone for further exploitation — particularly if chained with a sandbox escape vulnerability, which could lead to full system compromise, data exfiltration, or lateral movement. The attack requires no special privileges or user interaction beyond visiting a crafted HTML page (Chrome Releases, GitHub Advisory).
As of the disclosure date (August 20, 2026), there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is 0.0, reflecting low current exploitation probability, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported at this time (GitHub Advisory).
Google has released a patch in Chrome stable channel version 151.0.7922.173 for Linux and 151.0.7922.173/.174 for Windows and Mac. Users should immediately update Google Chrome to version 151.0.7922.173 or later via the browser's built-in update mechanism (Settings → Help → About Google Chrome) or by enabling automatic updates. As a temporary workaround where immediate patching is not feasible, organizations should restrict user access to untrusted or unknown websites (Chrome Releases, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."