
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-76023 is a sandbox escape vulnerability caused by improper resource control in the Linux Toolkit Theming component of Google Chrome. It affects all Chrome versions prior to 151.0.7922.173 on Linux (and prior to 151.0.7922.173/.174 on Windows/Mac). A remote attacker who has already compromised the renderer process can exploit this flaw to execute arbitrary code outside the Chrome sandbox via a crafted HTML page. The vulnerability was reported by Keita Sode and Daisuke Hatakeyama of SYZD Research on 2026-08-11 and publicly disclosed on 2026-08-20 alongside the Chrome 151.0.7922.173 stable channel release. It carries a Chromium security severity rating of High; a formal CVSS base score has not yet been published (Chrome Releases, GitHub Advisory).
The root cause is classified as CWE-913 (Improper Control of Dynamically-Managed Code Resources), meaning Chrome's Linux Toolkit Theming subsystem fails to properly restrict access to or manipulation of dynamically-managed code resources. This allows an attacker who has already gained control of the renderer process — typically through a separate renderer-level exploit — to leverage the theming component as a second-stage escape vector, breaking out of Chrome's sandbox and executing code with the privileges of the broader Chrome process on the host OS. The vulnerability is tracked internally at Chromium issue 545124048 (Chrome Releases, GitHub Advisory). No public proof-of-concept or detailed technical write-up has been released as of disclosure.
Successful exploitation allows an attacker to execute arbitrary code outside Chrome's sandbox with the privileges of the Chrome process on the underlying operating system. This can lead to full compromise of the user's session, access to sensitive local files, credential theft, installation of persistent malware, and potential lateral movement within a network. The impact is primarily a confidentiality and integrity risk to the host system, with availability also at risk if the attacker deploys destructive payloads (GitHub Advisory, Chrome Releases).
Exploitation requires a prior compromise of the Chrome renderer process, making this a chained vulnerability rather than a standalone remote code execution flaw. As of the disclosure date (2026-08-20), there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The EPSS score is reported as 0.0, and the vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (GitHub Advisory, Chrome Releases).
/bin/bash, sh, curl, wget, python) on Linux systems, particularly originating from chrome or chrome-sandbox parent processes./tmp, or Chrome profile directories created by the Chrome process; unexpected executables or scripts dropped on disk.auditd) showing privilege escalation or unexpected syscalls originating from Chrome renderer processes; browser crash reports or unexpected Chrome process terminations preceding suspicious activity.Google has released Chrome 151.0.7922.173 for Linux and 151.0.7922.173/.174 for Windows and Mac, which addresses this vulnerability. Users and organizations should update Chrome to version 151.0.7922.173 or later immediately. As a defense-in-depth measure, avoid visiting untrusted or suspicious websites, and consider enforcing Chrome update policies across the organization via enterprise management tools. No configuration-based workaround is available; patching is the only definitive remediation (Chrome Releases, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."