CVE-2024-6778

HIGH

Google Chrome <126.0.6478.182 - RCE

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2024-6778. PoCs published by ading2210, r00tjunip3r1.

AI-analyzed exploit summary This repository contains proof-of-concept exploits for CVE-2024-5836 and CVE-2024-6778, which are Chromium vulnerabilities allowing sandbox escape via browser extension. The exploits leverage race conditions and script injection to execute arbitrary JavaScript on privileged WebUI pages, leading to potential RCE.

Description

Race in DevTools in Google Chrome prior to 126.0.6478.182 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

Exploits (2)

nomisec WORKING POC 97 stars
by ading2210 · poc
https://github.com/ading2210/CVE-2024-6778-POC

This repository contains proof-of-concept exploits for CVE-2024-5836 and CVE-2024-6778, which are Chromium vulnerabilities allowing sandbox escape via browser extension. The exploits leverage race conditions and script injection to execute arbitrary JavaScript on privileged WebUI pages, leading to potential RCE.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: Chromium < 126.0.6478.54
No auth needed
Prerequisites: Victim must have a vulnerable version of Chromium installed · Attacker must convince victim to install a malicious extension
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 6 stars
by r00tjunip3r1 · poc
https://github.com/r00tjunip3r1/POC-CVE-2024-6778

This repository contains a proof-of-concept exploit for CVE-2024-6778, which involves a sandbox escape in Chromium via a browser extension. The exploit chain manipulates legacy browser support policies to achieve code execution in privileged WebUI pages.

Classification
Working Poc 90%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: Chromium < 126.0.6478.54
No auth needed
Prerequisites: Chromium version older than 126.0.6478.54 · Ability to install a malicious browser extension
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 7.5
EPSS 0.0073
EPSS Percentile 49.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-362 CWE-366
Status published
Products (1)
google/chrome < 126.0.6478.182
Published Jul 16, 2024
Tracked Since Feb 18, 2026