
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-76021 is a use-after-free vulnerability in the DOM component of Google Chrome that allows a remote attacker to execute arbitrary code inside the browser sandbox via a crafted HTML page. It affects all versions of Google Chrome prior to 151.0.7922.173 and was reported by Google BigSleep@Grape on August 2, 2026. The vulnerability was publicly disclosed on August 20, 2026, alongside a stable channel update. It carries a Chromium security severity rating of High (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), occurring in Chrome's DOM implementation. A use-after-free condition arises when memory associated with a DOM object is freed but a reference to that memory is retained and subsequently used, allowing an attacker to control the freed memory region and redirect code execution. Exploitation requires luring a victim to visit a specially crafted HTML page, making the attack vector network-based with user interaction required. The bug was tracked internally as Chromium issue 541854084 (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox. While sandbox containment limits direct host OS compromise, a sandbox escape (potentially chained with another vulnerability) could lead to full system compromise, data exfiltration, or installation of malware. All users running Chrome versions prior to 151.0.7922.173 on Windows, Mac, and Linux are at risk (Chrome Releases, GitHub Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is currently 0.0, reflecting low near-term exploitation probability. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported at this time.
Google has released a fix in Chrome stable channel version 151.0.7922.173 (Linux) and 151.0.7922.173/.174 (Windows and Mac). Users and organizations should update Chrome immediately via the browser's built-in update mechanism or through enterprise deployment tools. As a temporary workaround prior to patching, organizations can restrict access to untrusted or external web content and implement application allowlisting to enforce authorized browser versions (Chrome Releases).
The vulnerability was noted across security aggregation platforms including VulDB, SecurityOnline, and Radar by Offseq shortly after disclosure. Tenable released Nessus detection plugins (338406 and 338407) for the vulnerability on the same day as disclosure. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability tracking (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."