CVE-2026-79052
massUse-After-Free in Google Chrome Allows Sandbox-Escape Code Execution
CVE-2026-79052 is a use-after-free (CWE-416) memory-safety flaw in the Aura component of Google Chrome, which handles parts of the browser's windowing and UI layer. An attacker can trigger it by luring a user to open a crafted HTML page, since the flaw is reachable through normal web browsing with no privileges required. Successful exploitation allows a remote attacker to execute arbitrary code outside the browser sandbox, meaning full compromise of the host process rather than being confined to the renderer. Anyone running an affected Chrome release prior to 152.0.7977.65 is exposed, and Chrome's enormous install base means the population of potentially vulnerable browsers is very large. Exploitation status is currently quiet: the flaw is rated Critical (CVSS 9.6) but there is no known public proof-of-concept, it is not in CISA's KEV catalog, and EPSS estimates only a 0.4% chance of exploitation in the next 30 days.
What to do: Update Chrome to version 152.0.7977.65 or later on all endpoints, and fully restart the browser so the updated version takes effect. Inventory managed and unmanaged browsers (including user-installed and BYOD browsers) for versions below 152.0.7977.65 and prioritize hosts where users browse untrusted websites. Given the Critical rating and sandbox-escape impact, treat this as a high-priority patch even though no in-the-wild exploitation is currently reported.
| google chrome | prior to 152.0.7977.65 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.