SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-78937

CRITICAL · CVSS 9.6 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

A use-after-free vulnerability in the Search component of Google Chrome on Android versions prior to 152.0.7977.65 could allow remote attackers to execute arbitrary code outside the browser's sandbox by tricking users into interacting with a specially crafted HTML page. This issue poses a medium security risk and should be prioritized by organizations using affected versions of Chrome on Android devices, particularly those with a high reliance on mobile web applications.

CVE
CVE-2026-78937
Severity
CRITICAL
CVSS
9.6
EPSS
0.37%
Android Chrome

Original NVD Description

Use after free in Search in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Related CVEs

Other vulnerabilities affecting the same vendor(s)