Sceawere
Vulnerability Detail
CVE-2026-76023UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Chrome Linux Toolkit Theming Sandbox Escape
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 1d ago
- Vendor
- Product
- Chrome
- Attack Type
- Improper resource control
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-08-20T21:17:10.553Z",
"pubdate": "2026-08-20T21:17:10.553Z",
"executiveSummary": "An improper resource control vulnerability exists within the Linux Toolkit Theming component of Google Chrome prior to version 151.0.7922.173.\nThis security flaw enables a remote attacker who has already successfully compromised the renderer process to execute arbitrary code outside the browser sandbox context.\nThe vulnerability directly impacts Google Chrome deployments running on Linux operating systems utilizing specific toolkit theming mechanisms.\nThe primary risk implication is a complete bypass of the Chromium multi-process security sandbox boundary, potentially leading to unauthorized system access and local system compromise.\nAttacker capabilities require the preliminary compromise of the rendering engine, typically achieved through the delivery and processing of a malicious, crafted HTML page.\nSuccessful exploitation requires the victim to load the specially crafted HTML page within the browser, triggering the resource control failure inside the Linux Toolkit Theming subsystem.",
"technicalDetails": "The vulnerability resides in the Linux Toolkit Theming component of Google Chrome, specifically stemming from improper resource control mechanisms governing interactions between abstracted UI elements and underlying system toolkit resources.\nThe vulnerable component handles system theme rendering and resource allocation for Linux environments, failing to properly validate, restrict, or isolate resources exposed to untrusted contexts.\nAffected software versions include all Google Chrome releases prior to version 151.0.7922.173 on Linux platforms.\nAuthentication and privilege requirements for the initial exploitation vector are minimal; the attacker does not require valid user credentials or elevated local privileges beyond the capability to execute code within a compromised renderer process.\nThe attack vector involves network exposure via web content, where an attacker delivers a crafted HTML page designed to interact with or trigger behaviors in the Linux Toolkit Theming engine.\nThe step-by-step attack flow begins when a remote user navigates to a malicious URL or processes a crafted HTML page supplied by the attacker.\nThe attacker leverages a preliminary vulnerability or execution primitive to compromise the restricted renderer process.\nFrom the compromised renderer context, the attacker interacts with the Linux Toolkit Theming interface, exploiting the improper resource control flaw.\nBecause resource boundaries are incorrectly enforced by the theming implementation, the attacker is able to manipulate shared resources or manipulate control flow across the security boundary.\nThis abuse of resource allocation facilitates a sandbox escape, allowing the execution of arbitrary operating system code outside the confined renderer sandbox with the privileges of the browser application.\nPost-exploitation impact includes arbitrary code execution on the host system, potential access to user data, and further lateral movement depending on the user's execution context and local system hardening."
}