
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-76022 is a heap-based buffer overflow vulnerability in the Network component of Google Chrome that allows a remote attacker to execute arbitrary code outside the Chrome sandbox via a crafted HTML page. It affects all versions of Google Chrome prior to 151.0.7922.173. The vulnerability was reported by researcher "0xAlessandro" on August 7, 2026, and publicly disclosed on August 20, 2026, when Google released the patched stable channel update. It carries a Chromium security severity rating of High, with an EPSS score of 0.0 at time of publication (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow), occurring in Chrome's Network component where insufficient bounds checking allows heap memory to be overwritten when processing a specially crafted HTML page. An attacker can trigger the overflow remotely by luring a victim to visit a malicious webpage, with no authentication or user interaction beyond page load required. Successful exploitation results in code execution outside the Chrome sandbox, bypassing Chrome's primary isolation defense. The Chromium issue tracker entry is tracked under issue ID 543798025, though full technical details remain restricted pending broad user patching (Chrome Releases, GitHub Advisory).
Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code with the privileges of the Chrome process, entirely outside the browser sandbox. This means an attacker could compromise the underlying host system, access sensitive user data, install malware, or pivot to other systems on the network. The sandbox escape aspect is particularly severe, as it negates Chrome's primary security boundary and exposes the full operating system to attacker-controlled code (Chrome Releases, GitHub Advisory).
As of the disclosure date (August 20, 2026), there is no evidence of a public proof-of-concept exploit or active in-the-wild exploitation. The EPSS score is 0.0, reflecting low current exploitation probability. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog at this time. Bug details in the Chromium issue tracker (issue 543798025) remain restricted to limit exploitation risk while users update (GitHub Advisory, Chrome Releases).
Google has released a fix in Chrome stable channel version 151.0.7922.173 for Linux and 151.0.7922.173/.174 for Windows and Mac. Users and administrators should immediately update Google Chrome to version 151.0.7922.173 or later via the browser's built-in update mechanism or enterprise deployment tools. As a temporary measure prior to patching, organizations should restrict user access to untrusted or unknown websites and educate users to avoid clicking links from unverified sources (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."