ZeroHour

CVE-2026-79052

mass

Use-After-Free in Google Chrome Allows Sandbox-Escape Code Execution

CVSS 3.1
9.6 critical
EPSS
<1%p37
Published
()
Modified
AI analysis

CVE-2026-79052 is a use-after-free (CWE-416) memory-safety flaw in the Aura component of Google Chrome, which handles parts of the browser's windowing and UI layer. An attacker can trigger it by luring a user to open a crafted HTML page, since the flaw is reachable through normal web browsing with no privileges required. Successful exploitation allows a remote attacker to execute arbitrary code outside the browser sandbox, meaning full compromise of the host process rather than being confined to the renderer. Anyone running an affected Chrome release prior to 152.0.7977.65 is exposed, and Chrome's enormous install base means the population of potentially vulnerable browsers is very large. Exploitation status is currently quiet: the flaw is rated Critical (CVSS 9.6) but there is no known public proof-of-concept, it is not in CISA's KEV catalog, and EPSS estimates only a 0.4% chance of exploitation in the next 30 days.

What to do: Update Chrome to version 152.0.7977.65 or later on all endpoints, and fully restart the browser so the updated version takes effect. Inventory managed and unmanaged browsers (including user-installed and BYOD browsers) for versions below 152.0.7977.65 and prioritize hosts where users browse untrusted websites. Given the Critical rating and sandbox-escape impact, treat this as a high-priority patch even though no in-the-wild exploitation is currently reported.

Affected
google chromeprior to 152.0.7977.65
Estimated exposure
mass≈3 billion+ Chrome installations/users (Chrome's global browser install base) — Chrome is the world's dominant browser with a publicly reported multi-billion-user install base, and all users below the fixed release are potentially affected until they update.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Aura in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.