ZeroHour

CVE-2026-79054

mass

Use-After-Free in Google Chrome Chromecast Enables Sandbox Escape

CVSS 3.1
8.3 high
EPSS
<1%p31
Published
()
Modified
AI analysis

CVE-2026-79054 is a use-after-free memory-corruption flaw (CWE-416) in the Chromecast component of Google Chrome. It is triggered when a user visits a crafted HTML page, but exploitation requires that the attacker has already compromised the renderer process, making this typically a second-stage or chained bug. A successful attacker executes arbitrary code outside of the browser sandbox, gaining code execution with privileges beyond Chrome's normal containment. All Google Chrome releases prior to 152.0.7977.65 are affected. No public proof-of-concept, in-the-wild exploitation, or KEV listing is currently known, and EPSS estimates only a 0.4% probability of exploitation within 30 days.

What to do: Update Google Chrome to version 152.0.7977.65 or later, available via Chrome's built-in updater (check at chrome://settings/help); force a browser refresh across managed fleets and confirm updated versions on all endpoints. Because exploitation requires a compromised renderer, patching renderer-component flaws and keeping Chrome current overall is the primary mitigation; treat visits to untrusted pages as the exposure vector.

Affected
Google ChromeAll versions prior to 152.0.7977.65
Estimated exposure
mass≈3+ billion Chrome users/installations across desktop and Android — Chrome is the world's most widely used browser with over three billion users per public market-share estimates, and the affected Chromecast component ships in all Chrome builds.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Chromecast in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Critical)

Vendors
google
Products
chrome
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.