CVE-2026-76021
Google Chrome vulnerability analysis and mitigation

Overview

CVE-2026-76021 is a use-after-free vulnerability in the DOM component of Google Chrome that allows a remote attacker to execute arbitrary code inside the browser sandbox via a crafted HTML page. It affects all versions of Google Chrome prior to 151.0.7922.173 and was reported by Google BigSleep@Grape on August 2, 2026. The vulnerability was publicly disclosed on August 20, 2026, alongside a stable channel update. It carries a Chromium security severity rating of High (Chrome Releases, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-416 (Use After Free), occurring in Chrome's DOM implementation. A use-after-free condition arises when memory associated with a DOM object is freed but a reference to that memory is retained and subsequently used, allowing an attacker to control the freed memory region and redirect code execution. Exploitation requires luring a victim to visit a specially crafted HTML page, making the attack vector network-based with user interaction required. The bug was tracked internally as Chromium issue 541854084 (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox. While sandbox containment limits direct host OS compromise, a sandbox escape (potentially chained with another vulnerability) could lead to full system compromise, data exfiltration, or installation of malware. All users running Chrome versions prior to 151.0.7922.173 on Windows, Mac, and Linux are at risk (Chrome Releases, GitHub Advisory).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is currently 0.0, reflecting low near-term exploitation probability. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported at this time.

Exploitation steps

  1. Reconnaissance: Identify targets running Google Chrome versions prior to 151.0.7922.173 on Windows, Mac, or Linux.
  2. Craft malicious HTML page: Develop a specially crafted HTML page that triggers the use-after-free condition in Chrome's DOM engine — for example, by manipulating DOM object lifecycles to free memory while retaining a dangling reference.
  3. Deliver the payload: Host the malicious HTML page on an attacker-controlled server and lure the victim to visit it via phishing, malvertising, or a compromised website.
  4. Trigger the vulnerability: When the victim's Chrome browser renders the page, the use-after-free condition is triggered, allowing the attacker to control freed memory and redirect execution flow.
  5. Execute arbitrary code in sandbox: The attacker achieves arbitrary code execution within the Chrome renderer sandbox, potentially chaining with a sandbox escape vulnerability for full system access (Chrome Releases).

Mitigation and workarounds

Google has released a fix in Chrome stable channel version 151.0.7922.173 (Linux) and 151.0.7922.173/.174 (Windows and Mac). Users and organizations should update Chrome immediately via the browser's built-in update mechanism or through enterprise deployment tools. As a temporary workaround prior to patching, organizations can restrict access to untrusted or external web content and implement application allowlisting to enforce authorized browser versions (Chrome Releases).

Community reactions

The vulnerability was noted across security aggregation platforms including VulDB, SecurityOnline, and Radar by Offseq shortly after disclosure. Tenable released Nessus detection plugins (338406 and 338407) for the vulnerability on the same day as disclosure. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability tracking (Chrome Releases).

Additional resources


SourceThis report was generated using AI

Related Google Chrome vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-76023NONEN/A
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesAug 20, 2026
CVE-2026-76022NONEN/A
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesAug 20, 2026
CVE-2026-76021NONEN/A
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesAug 20, 2026
CVE-2026-76020NONEN/A
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesAug 20, 2026
CVE-2026-76019NONEN/A
  • Google Chrome logoGoogle Chrome
  • cpe:2.3:a:google:chrome
NoYesAug 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management