CVE-2026-76018: Privilege elevation in Import
Published May 16, 2026
·Updated
Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially execute arbitrary code outside the sandbox via a crafted file. (Chromium security severity: High)
Credit
Google
Affected Software
1 affected componentFixes available
Google Chrome<151.0.7922.173
151.0.7922.173
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 151.0.7922.173
Event History
May 16, 2026
CVE Published
12:00 AM
Data Sourced
12:00 AM
SeverityWeaknessAffected Software
Aug 20, 2026
CVE Published
via MITRE·08:51 PM
Data Sourced
via MITRE·08:51 PM
DescriptionWeakness
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What severity and risk rating are assigned to this issue?
The issue is rated high severity with a risk score of 33.
2
Which software is identified as affected?
The affected software is Google Chrome by Google.
3
Where can I find the vendor's related release information?
A Google Chrome Releases blog reference is provided: https://chromereleases.googleblog.com/2026/08/stable-channel-update-for-desktop_0404570826.html