CyberRota Analysis
AI-GeneratedA use-after-free vulnerability in the Compositing component of Google Chrome prior to version 152.0.7977.65 can be exploited by remote attackers to execute arbitrary code within the browser's sandbox environment through a specially crafted HTML page. This poses a medium security risk, and organizations using affected versions of Chrome should prioritize updates to mitigate potential exploitation.
CVE
CVE-2026-78990
Severity
HIGH
CVSS
8.8
EPSS
0.55%
Chrome
Original NVD Description
Use after free in Compositing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)
Related CVEs
Other vulnerabilities affecting the same vendor(s)