CVE-2026-79054
massUse-After-Free in Google Chrome Chromecast Enables Sandbox Escape
CVE-2026-79054 is a use-after-free memory-corruption flaw (CWE-416) in the Chromecast component of Google Chrome. It is triggered when a user visits a crafted HTML page, but exploitation requires that the attacker has already compromised the renderer process, making this typically a second-stage or chained bug. A successful attacker executes arbitrary code outside of the browser sandbox, gaining code execution with privileges beyond Chrome's normal containment. All Google Chrome releases prior to 152.0.7977.65 are affected. No public proof-of-concept, in-the-wild exploitation, or KEV listing is currently known, and EPSS estimates only a 0.4% probability of exploitation within 30 days.
What to do: Update Google Chrome to version 152.0.7977.65 or later, available via Chrome's built-in updater (check at chrome://settings/help); force a browser refresh across managed fleets and confirm updated versions on all endpoints. Because exploitation requires a compromised renderer, patching renderer-component flaws and keeping Chrome current overall is the primary mitigation; treat visits to untrusted pages as the exposure vector.
| Google Chrome | All versions prior to 152.0.7977.65 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)
- Vendors
- Products
- chrome
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.